CVE-2026-51659
moderateUnauthenticated information disclosure in TOTOLINK T6 router (DMZ config leak)
CVE-2026-51659 is an improper access control flaw (CWE-284) in the getUrlFilterRules function of TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker triggers it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, which the function fails to protect with an authentication check. The attacker gains read access to the device's DMZ configuration, which typically reveals the internal IP addresses of exposed hosts — useful reconnaissance for follow-up attacks — but cannot modify settings or disrupt the device (CVSS 7.5, confidentiality-only impact). Any TOTOLINK T6 running the named firmware build is affected; other builds or models have not been confirmed in the available data. No public proof-of-concept, KEV listing, or in-the-wild exploitation is known; EPSS estimates only a 0.4% probability of exploitation within 30 days.
What to do: Inventory for TOTOLINK T6 units running firmware 4.1.5cu.748_B20211015 and apply the latest TOTOLINK firmware when a fixed build is published (no fixed version is confirmed in the available data). Until patched, keep the web management interface off the WAN or restrict access to trusted LAN sources, since exploitation only requires network reachability to /cgi-bin/cstecgi.cgi. Because the flaw only exposes DMZ configuration, treat it mainly as reconnaissance risk, but watch for unauthenticated POSTs to that endpoint from untrusted addresses.
| TOTOLINK T6 router | firmware 4.1.5cu.748_B20211015 (only this build is reported affected; broader version ranges not confirmed) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DMZ configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.