CVE-2026-51650
moderateUnauthenticated info disclosure in TOTOLINK T6 router via getRemoteCfg
TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an incorrect access control flaw (CWE-284) in the getRemoteCfg function of its web management interface. An unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi over the network, with no credentials or user interaction required. Successful exploitation discloses whether remote management is enabled and the port it uses, which is primarily useful reconnaissance for follow-up attacks against the router's administration interface. Owners and operators of TOTOLINK T6 routers running the affected firmware are exposed, particularly when the management interface is reachable from the internet. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.4% chance of exploitation in the next 30 days.
What to do: Check your T6 firmware version and, if running 4.1.5cu.748_B20211015, consult TOTOLINK's support site for updated firmware, as no fixed version is specified in the available data. Until patched, restrict WAN access to the router's management interface or disable remote administration, since the leak reveals the remote-management port and aids targeting. Consider monitoring or firewalling unauthenticated POST requests to /cgi-bin/cstecgi.cgi from untrusted networks.
| TOTOLINK T6 router (web management interface, /cgi-bin/cstecgi.cgi, getRemoteCfg function) | 4.1.5cu.748_B20211015 (the only version cited; other firmware versions are unconfirmed) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain remote-management enablement and port information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.