ZeroHour

CVE-2026-51644

Unauthenticated information disclosure in TOTOLINK T6 router

CVSS 3.1
7.5 high
EPSS
<1%p30
Published
()
Modified
AI analysis

TOTOLINK T6 wireless router firmware 4.1.5cu.748_B20211015 contains an improper access control flaw (CWE-284) in the getCrpcConfig function of its web management interface. A remote, unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi, bypassing the access control on that endpoint. Successful requests disclose the device's cloud remote-control status and associated URL information; per the CVSS vector this is a confidentiality-only issue, with no indication of code execution or configuration changes. Any T6 router whose management interface is reachable by an attacker, such as units with remote management exposed on the WAN or on an untrusted network segment, is affected. No public proof-of-concept is known, the flaw is not listed in CISA KEV, and EPSS estimates only a 0.4% probability of exploitation within 30 days (30th percentile), so exploitation is not currently confirmed.

What to do: Check whether T6 units run firmware 4.1.5cu.748_B20211015 and avoid exposing the router's web management interface to the internet (disable WAN/remote management or restrict access with a firewall) until TOTOLINK publishes a fix; no patched version is specified in the available data. The information exposed is limited to cloud remote-control status and URLs, so immediate risk is low, but monitor TOTOLINK advisories for a patched firmware release.

Affected
TOTOLINK T6 wireless router4.1.5cu.748_B20211015 (the only version confirmed affected; other firmware versions are unverified)
Estimated exposure
unknown (no public install-base or scan counts specific to this model) — No public active-install, market-share, or internet-scan data is available for the TOTOLINK T6 specifically, and the practically exposed population is likely limited to deployed units whose web management interface is reachable from…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getCrpcConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.