CVE-2026-51644
Unauthenticated information disclosure in TOTOLINK T6 router
TOTOLINK T6 wireless router firmware 4.1.5cu.748_B20211015 contains an improper access control flaw (CWE-284) in the getCrpcConfig function of its web management interface. A remote, unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi, bypassing the access control on that endpoint. Successful requests disclose the device's cloud remote-control status and associated URL information; per the CVSS vector this is a confidentiality-only issue, with no indication of code execution or configuration changes. Any T6 router whose management interface is reachable by an attacker, such as units with remote management exposed on the WAN or on an untrusted network segment, is affected. No public proof-of-concept is known, the flaw is not listed in CISA KEV, and EPSS estimates only a 0.4% probability of exploitation within 30 days (30th percentile), so exploitation is not currently confirmed.
What to do: Check whether T6 units run firmware 4.1.5cu.748_B20211015 and avoid exposing the router's web management interface to the internet (disable WAN/remote management or restrict access with a firewall) until TOTOLINK publishes a fix; no patched version is specified in the available data. The information exposed is limited to cloud remote-control status and URLs, so immediate risk is low, but monitor TOTOLINK advisories for a patched firmware release.
| TOTOLINK T6 wireless router | 4.1.5cu.748_B20211015 (the only version confirmed affected; other firmware versions are unverified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getCrpcConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.