CVE-2026-51657
moderateUnauthenticated access control flaw exposes syslog config on TOTOLINK T6
CVE-2026-51657 is an incorrect access control flaw (CWE-284) in the getSyslogCfg function of TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An unauthenticated remote attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, requiring no credentials or user interaction. Successful exploitation lets the attacker retrieve syslog-related configuration from the device, potentially revealing logging destinations and network details; the assigned CVSS 3.1 score of 9.1 rates confidentiality and integrity impact as high even though the description frames the direct gain as access to this configuration. Affected parties are users of TOTOLINK T6 routers running the listed firmware version; no other models or versions are named in the available data. No public proof-of-concept or known exploitation exists at this time, with an EPSS of roughly 0.4% (30th percentile) and no CISA KEV listing.
What to do: Inventory any TOTOLINK T6 routers and check whether firmware 4.1.5cu.748_B20211015 is installed, then apply a fixed firmware from TOTOLINK when released (no fixed version is named in the current data). Until patching is possible, avoid exposing the router's web management interface to the internet, or restrict access to /cgi-bin/cstecgi.cgi to trusted sources only. No public PoC or in-the-wild exploitation is known, but TOTOLINK devices are routinely scanned by automated attackers, so prompt mitigation is still warranted for internet-facing units.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain syslog-related configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.