ZeroHour

CVE-2026-51636

large

Unauthenticated Wi-Fi ACL rule disclosure in TOTOLINK T6 router

CVSS 3.1
9.1 critical
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51636 is an improper access-control flaw (CWE-284) in the getWiFiAclRules function of TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi web management endpoint, with no credentials or user interaction required. On success, the attacker can read the router's Wi-Fi access-control list — the configured rules describing which client devices are allowed or blocked from the wireless network — which the 9.1 CVSS score reflects as a high-impact information disclosure. Administrators and owners of TOTOLINK T6 routers running the named firmware are affected, especially where the web interface is reachable from the internet or from untrusted networks. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only about a 0.4% chance of exploitation within 30 days, so no exploitation is known as of publication.

What to do: Check the running firmware version on any TOTOLINK T6 (visible on the router's status page) and, because the advisory names no fixed build, monitor TOTOLINK's support site for a patched release before upgrading. As interim mitigation, do not expose the router's web administration interface to the WAN (disable remote management or restrict it to the trusted LAN) so unauthenticated POSTs to /cgi-bin/cstecgi.cgi cannot reach the device. Note that the ACL contents returned to an attacker can reveal information about permitted and blocked client devices, so review those rules for anything sensitive after patching.

Affected
TOTOLINK T6 routerfirmware 4.1.5cu.748_B20211015 (the only version named in the advisory; other builds may also be affected but are not confirmed in the data)
Estimated exposure
largelikely on the order of tens of thousands of deployed TOTOLINK T6 routers (exact install base unpublished) — TOTOLINK publishes no install counts, so the estimate is extrapolated from public internet scans that consistently show tens of thousands of exposed TOTOLINK consumer routers across models, combined with the T6's role as a mainstream…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.