ZeroHour

CVE-2026-51647

moderate

Unauthenticated information disclosure in TOTOLINK T6 cloud control API

CVSS 3.1
7.5 high
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51647 is an improper access control flaw (CWE-284) in the getCrpcCfg function of the TOTOLINK T6 router's web management interface. An unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi, with no login or user interaction required. Successful exploitation discloses the device's cloud remote-control status and associated URL information, giving attackers reconnaissance material about the device's cloud connectivity; the CVSS score of 7.5 (AV:N/AC:L/PR:N/UI:N, confidentiality-only) confirms there is no direct integrity or availability impact. Any TOTOLINK T6 running firmware 4.1.5cu.748_B20211015 is affected, and devices whose web interface is reachable from the internet are at the greatest risk. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates only a 0.4% chance of exploitation within 30 days.

What to do: Check whether your T6 runs firmware 4.1.5cu.748_B20211015 and check TOTOLINK's support/download page for a patched release, as no fixed version is confirmed in the available data. Until a fix is available, restrict the router's management interface to the LAN only and disable WAN/remote management or firewall access to /cgi-bin/cstecgi.cgi from untrusted networks. Because the impact is limited to disclosure of cloud remote-control status and URLs, treat this primarily as a reconnaissance risk and review firewall logs for unauthenticated POSTs to cstecgi.cgi.

Affected
TOTOLINK T6 router/mesh Wi-Fi system (getCrpcCfg function in /cgi-bin/cstecgi.cgi)4.1.5cu.748_B20211015 (the only firmware build confirmed in the advisory; other 4.1.5cu builds may also be affected but are unconfirmed)
Estimated exposure
moderate≈1,000–10,000 internet-exposed T6 units (a single-model subset of the tens of thousands of TOTOLINK devices visible in public internet scans) — Public internet scans routinely show tens of thousands of TOTOLINK routers exposing their cstecgi.cgi web API, but the T6 is one consumer mesh model within that installed base, so the plausible exposed population for this specific flaw is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getCrpcCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.