CVE-2026-51647
moderateUnauthenticated information disclosure in TOTOLINK T6 cloud control API
CVE-2026-51647 is an improper access control flaw (CWE-284) in the getCrpcCfg function of the TOTOLINK T6 router's web management interface. An unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi, with no login or user interaction required. Successful exploitation discloses the device's cloud remote-control status and associated URL information, giving attackers reconnaissance material about the device's cloud connectivity; the CVSS score of 7.5 (AV:N/AC:L/PR:N/UI:N, confidentiality-only) confirms there is no direct integrity or availability impact. Any TOTOLINK T6 running firmware 4.1.5cu.748_B20211015 is affected, and devices whose web interface is reachable from the internet are at the greatest risk. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates only a 0.4% chance of exploitation within 30 days.
What to do: Check whether your T6 runs firmware 4.1.5cu.748_B20211015 and check TOTOLINK's support/download page for a patched release, as no fixed version is confirmed in the available data. Until a fix is available, restrict the router's management interface to the LAN only and disable WAN/remote management or firewall access to /cgi-bin/cstecgi.cgi from untrusted networks. Because the impact is limited to disclosure of cloud remote-control status and URLs, treat this primarily as a reconnaissance risk and review firewall logs for unauthenticated POSTs to cstecgi.cgi.
| TOTOLINK T6 router/mesh Wi-Fi system (getCrpcCfg function in /cgi-bin/cstecgi.cgi) | 4.1.5cu.748_B20211015 (the only firmware build confirmed in the advisory; other 4.1.5cu builds may also be affected but are unconfirmed) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getCrpcCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.