CVE-2026-51663
nicheUnauthenticated access-control flaw in TOTOLINK T6 wireless scan function
TOTOLINK T6 router firmware 4.1.5cu.748_B20211015 fails to enforce access control on the getWiFiApcliScan function in its web management interface. An unauthenticated attacker who can reach the router's management interface can send a crafted POST request to /cgi-bin/cstecgi.cgi to trigger wireless AP-client scans and retrieve the resulting scan data. The disclosed information reveals nearby access points and the router's Wi-Fi client connection details; while the CVSS 3.1 score is 9.8 (critical) with high confidentiality, integrity, and availability impact, the described behavior is limited to triggering scans and reading scan results. Any TOTOLINK T6 running the affected firmware is exposed, with risk concentrated on routers whose management interface is reachable from the WAN or from untrusted LAN clients. No public proof-of-concept, KEV listing, or known in-the-wild exploitation exists, and EPSS puts 30-day exploitation probability at 0.5%.
What to do: Check whether any TOTOLINK T6 routers in your environment run firmware 4.1.5cu.748_B20211015 and monitor the vendor for a corrected firmware release, since no fixed version is listed in the available data. As an interim mitigation, restrict access to the router's management interface (in particular /cgi-bin/cstecgi.cgi) from untrusted networks by disabling WAN-side remote management and limiting LAN access to trusted clients.
| TOTOLINK T6 | firmware 4.1.5cu.748_B20211015 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger wireless scans and retrieve AP-client scan results via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.