CVE-2026-51658
moderateUnauthenticated information disclosure in TOTOLINK T6 router
TOTOLINK T6 router firmware 4.1.5cu.748_B20211015 contains an improper access control flaw (CWE-284) in the getDmzCfg function of its web management interface. An unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi, which returns the router's DMZ configuration without requiring any credentials. The attacker gains read access to DMZ settings — revealing which internal hosts are exposed and related parameters — which is useful reconnaissance for follow-on attacks; the CVSS 7.5 score reflects a confidentiality-only issue (no integrity or availability impact). Only the TOTOLINK T6 on the listed firmware build is documented as affected, and successful exploitation requires the router's management interface to be reachable by the attacker (LAN-side or via exposed remote management). No public proof-of-concept exists, the flaw is not in CISA's KEV, and the EPSS of 0.4% indicates a low likelihood of near-term exploitation.
What to do: Check the firmware version on any TOTOLINK T6 in your estate (units on 4.1.5cu.748_B20211015 are affected) and, until TOTOLINK publishes a fixed firmware, restrict the web management interface to trusted LAN segments and disable WAN-side/remote management access to /cgi-bin/cstecgi.cgi. No fixed version is confirmed in available disclosures, so monitor the vendor's support/download page for firmware newer than 4.1.5cu.748_B20211015. Organizations using the DMZ feature on exposed units should prioritize review, since the leak reveals internal host placement.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (the only build documented as affected; other versions unconfirmed) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DMZ configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.