CVE-2026-51643
moderateUnauthenticated information disclosure in TOTOLINK T6 router firmware
CVE-2026-51643 is an incorrect access control flaw (CWE-284) in the getNtpCfg function of TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. An unauthenticated remote attacker can trigger it by sending a crafted POST request to the router's web API endpoint /cgi-bin/cstecgi.cgi, which invokes getNtpCfg without requiring any login. On success, the attacker obtains the device's NTP configuration and current time data, an information-disclosure condition that the CVSS 3.1 score rates critical (9.1). Users and administrators running the affected TOTOLINK T6 firmware are affected, particularly where the router's management interface is reachable from the internet. No public proof-of-concept, no listing in CISA's KEV, and a low EPSS probability (0.4% over 30 days) indicate that exploitation has not yet been confirmed in the wild.
What to do: Check any TOTOLINK T6 unit for firmware 4.1.5cu.748_B20211015 and apply the vendor's fixed firmware when TOTOLINK publishes it (no fixed version is specified in the available data). Until then, do not expose the management interface to the internet — restrict /cgi-bin/cstecgi.cgi access to trusted LAN/management networks — and monitor for unauthenticated POST requests to that endpoint targeting getNtpCfg.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (firmware; only this build is named in the disclosure, other versions/ranges unverified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain NTP configuration and current time data via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.