ZeroHour

CVE-2026-51663

niche

Unauthenticated access-control flaw in TOTOLINK T6 wireless scan function

CVSS 3.1
9.8 critical
EPSS
<1%p40
Published
()
Modified
AI analysis

TOTOLINK T6 router firmware 4.1.5cu.748_B20211015 fails to enforce access control on the getWiFiApcliScan function in its web management interface. An unauthenticated attacker who can reach the router's management interface can send a crafted POST request to /cgi-bin/cstecgi.cgi to trigger wireless AP-client scans and retrieve the resulting scan data. The disclosed information reveals nearby access points and the router's Wi-Fi client connection details; while the CVSS 3.1 score is 9.8 (critical) with high confidentiality, integrity, and availability impact, the described behavior is limited to triggering scans and reading scan results. Any TOTOLINK T6 running the affected firmware is exposed, with risk concentrated on routers whose management interface is reachable from the WAN or from untrusted LAN clients. No public proof-of-concept, KEV listing, or known in-the-wild exploitation exists, and EPSS puts 30-day exploitation probability at 0.5%.

What to do: Check whether any TOTOLINK T6 routers in your environment run firmware 4.1.5cu.748_B20211015 and monitor the vendor for a corrected firmware release, since no fixed version is listed in the available data. As an interim mitigation, restrict access to the router's management interface (in particular /cgi-bin/cstecgi.cgi) from untrusted networks by disabling WAN-side remote management and limiting LAN access to trusted clients.

Affected
TOTOLINK T6firmware 4.1.5cu.748_B20211015
Estimated exposure
nicheroughly low thousands of T6 units exposed via WAN-reachable management interfaces (public scans show tens of thousands of TOTOLINK devices internet-exposed… — Internet-wide scan data typically shows tens of thousands of TOTOLINK devices exposed online across all models, and the T6 with this specific firmware is one model among them, with many consumer units additionally shielded behind NAT.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger wireless scans and retrieve AP-client scan results via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.