ZeroHour

CVE-2026-51649

moderate

Incorrect access control in TOTOLINK T6 exposes diagnostic config and ping logs

CVSS 3.1
9.1 critical
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51649 is an incorrect access-control flaw (CWE-284) in the getDiagnosisCfg function of TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, which returns diagnostic configuration and ping log contents without requiring any credentials. The attacker gains read access to diagnostic settings and ping logs, which can reveal internal network details such as hosts and addresses the router has pinged, potentially aiding further reconnaissance; the flaw carries a published CVSS 3.1 base score of 9.1 (critical). Anyone operating a TOTOLINK T6 on the affected firmware, typically home or small-office deployments, is affected, particularly when the management interface is reachable from the WAN. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates a 0.4% probability of exploitation within 30 days.

What to do: Check the firmware version on any TOTOLINK T6 and upgrade to the latest firmware published by TOTOLINK once a fixed build is released (no fixed version is specified in the available data). Until patching is possible, avoid exposing the router's web management interface to the WAN and limit access to trusted clients, and monitor for unsolicited POST requests to /cgi-bin/cstecgi.cgi. Because the impact is read-only disclosure of diagnostic configuration and ping logs, treat leaked log contents as potentially revealing internal network details.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (the version named in the advisory; other versions/ranges are not specified in the available data)
Estimated exposure
moderate≈10k–100k affected devices (estimate; TOTOLINK cstecgi.cgi endpoints number in the tens of thousands in public scans, with only a subset on affected T6… — Based on deployment patterns for budget TOTOLINK consumer routers and typical internet-exposed device counts for TOTOLINK's cstecgi.cgi management interface seen in public scans, of which only a fraction would be T6 units on the named…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain diagnostic configuration and ping log contents via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.