ZeroHour

CVE-2026-51671

large

Unauthenticated info disclosure in TOTOLINK T6 router (getCloudDownloadStatus)

CVSS 3.1
7.5 high
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51671 is an incorrect access control flaw (CWE-284) in the getCloudDownloadStatus function of TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An unauthenticated attacker triggers it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, requiring no credentials or user interaction. The flaw only leaks cloud firmware download state information; the CVSS vector (C:H/I:N/A:N) confirms confidentiality-only impact, with no ability to alter device configuration or disrupt service. Any TOTOLINK T6 running this firmware is affected, with risk concentrated on routers whose web management interface is reachable from the internet. No public proof-of-concept, in-the-wild exploitation, or KEV listing is known, and EPSS assigns roughly a 0.4% probability of exploitation within 30 days, so current risk is low.

What to do: Check whether T6 routers are running firmware 4.1.5cu.748_B20211015 and install a patched release from TOTOLINK's support site when one is published; no fixed version is specified in the available data. Until patched, do not expose the router's web management interface or the /cgi-bin/cstecgi.cgi endpoint to the internet and restrict administration to trusted networks. Current impact is limited to disclosure of cloud firmware download state, but unauthenticated cstecgi.cgi handlers are a frequently targeted TOTOLINK attack surface, so keep exposed devices off the public internet.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (the only version named in the available data; scope across other firmware versions not specified)
Estimated exposure
largeLikely tens of thousands of internet-exposed TOTOLINK devices, with the total installed T6 base plausibly in the hundreds of thousands (estimate) — TOTOLINK consumer routers regularly appear in public internet-wide scans in the tens of thousands and the T6 is one of the brand's widely sold budget models, but per-model counts are unpublished, so this is an order-of-magnitude estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getCloudDownloadStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware download state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.