CVE-2026-51649
moderateIncorrect access control in TOTOLINK T6 exposes diagnostic config and ping logs
CVE-2026-51649 is an incorrect access-control flaw (CWE-284) in the getDiagnosisCfg function of TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, which returns diagnostic configuration and ping log contents without requiring any credentials. The attacker gains read access to diagnostic settings and ping logs, which can reveal internal network details such as hosts and addresses the router has pinged, potentially aiding further reconnaissance; the flaw carries a published CVSS 3.1 base score of 9.1 (critical). Anyone operating a TOTOLINK T6 on the affected firmware, typically home or small-office deployments, is affected, particularly when the management interface is reachable from the WAN. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates a 0.4% probability of exploitation within 30 days.
What to do: Check the firmware version on any TOTOLINK T6 and upgrade to the latest firmware published by TOTOLINK once a fixed build is released (no fixed version is specified in the available data). Until patching is possible, avoid exposing the router's web management interface to the WAN and limit access to trusted clients, and monitor for unsolicited POST requests to /cgi-bin/cstecgi.cgi. Because the impact is read-only disclosure of diagnostic configuration and ping logs, treat leaked log contents as potentially revealing internal network details.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 (the version named in the advisory; other versions/ranges are not specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain diagnostic configuration and ping log contents via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.