ZeroHour

CVE-2026-51659

moderate

Unauthenticated information disclosure in TOTOLINK T6 router (DMZ config leak)

CVSS 3.1
7.5 high
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51659 is an improper access control flaw (CWE-284) in the getUrlFilterRules function of TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker triggers it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, which the function fails to protect with an authentication check. The attacker gains read access to the device's DMZ configuration, which typically reveals the internal IP addresses of exposed hosts — useful reconnaissance for follow-up attacks — but cannot modify settings or disrupt the device (CVSS 7.5, confidentiality-only impact). Any TOTOLINK T6 running the named firmware build is affected; other builds or models have not been confirmed in the available data. No public proof-of-concept, KEV listing, or in-the-wild exploitation is known; EPSS estimates only a 0.4% probability of exploitation within 30 days.

What to do: Inventory for TOTOLINK T6 units running firmware 4.1.5cu.748_B20211015 and apply the latest TOTOLINK firmware when a fixed build is published (no fixed version is confirmed in the available data). Until patched, keep the web management interface off the WAN or restrict access to trusted LAN sources, since exploitation only requires network reachability to /cgi-bin/cstecgi.cgi. Because the flaw only exposes DMZ configuration, treat it mainly as reconnaissance risk, but watch for unauthenticated POSTs to that endpoint from untrusted addresses.

Affected
TOTOLINK T6 routerfirmware 4.1.5cu.748_B20211015 (only this build is reported affected; broader version ranges not confirmed)
Estimated exposure
moderatelikely tens of thousands of devices worldwide at most (single model, single confirmed firmware build) — TOTOLINK is a budget consumer/SOHO router brand with no published install base, and public internet scans have historically surfaced thousands of TOTOLINK devices, so one model limited to one firmware build plausibly caps out in the low…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DMZ configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.