ZeroHour

CVE-2026-51643

moderate

Unauthenticated information disclosure in TOTOLINK T6 router firmware

CVSS 3.1
9.1 critical
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51643 is an incorrect access control flaw (CWE-284) in the getNtpCfg function of TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. An unauthenticated remote attacker can trigger it by sending a crafted POST request to the router's web API endpoint /cgi-bin/cstecgi.cgi, which invokes getNtpCfg without requiring any login. On success, the attacker obtains the device's NTP configuration and current time data, an information-disclosure condition that the CVSS 3.1 score rates critical (9.1). Users and administrators running the affected TOTOLINK T6 firmware are affected, particularly where the router's management interface is reachable from the internet. No public proof-of-concept, no listing in CISA's KEV, and a low EPSS probability (0.4% over 30 days) indicate that exploitation has not yet been confirmed in the wild.

What to do: Check any TOTOLINK T6 unit for firmware 4.1.5cu.748_B20211015 and apply the vendor's fixed firmware when TOTOLINK publishes it (no fixed version is specified in the available data). Until then, do not expose the management interface to the internet — restrict /cgi-bin/cstecgi.cgi access to trusted LAN/management networks — and monitor for unauthenticated POST requests to that endpoint targeting getNtpCfg.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (firmware; only this build is named in the disclosure, other versions/ranges unverified)
Estimated exposure
moderate≈ thousands of internet-exposed TOTOLINK routers, with the T6 model only a subset; exact T6 counts unknown — No per-model install counts are published for the T6, so the estimate is based on TOTOLINK consumer/SOHO routers routinely appearing in internet-wide scans with the cstecgi.cgi web interface exposed to the WAN.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain NTP configuration and current time data via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.