CVE-2026-51671
largeUnauthenticated info disclosure in TOTOLINK T6 router (getCloudDownloadStatus)
CVE-2026-51671 is an incorrect access control flaw (CWE-284) in the getCloudDownloadStatus function of TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An unauthenticated attacker triggers it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, requiring no credentials or user interaction. The flaw only leaks cloud firmware download state information; the CVSS vector (C:H/I:N/A:N) confirms confidentiality-only impact, with no ability to alter device configuration or disrupt service. Any TOTOLINK T6 running this firmware is affected, with risk concentrated on routers whose web management interface is reachable from the internet. No public proof-of-concept, in-the-wild exploitation, or KEV listing is known, and EPSS assigns roughly a 0.4% probability of exploitation within 30 days, so current risk is low.
What to do: Check whether T6 routers are running firmware 4.1.5cu.748_B20211015 and install a patched release from TOTOLINK's support site when one is published; no fixed version is specified in the available data. Until patched, do not expose the router's web management interface or the /cgi-bin/cstecgi.cgi endpoint to the internet and restrict administration to trusted networks. Current impact is limited to disclosure of cloud firmware download state, but unauthenticated cstecgi.cgi handlers are a frequently targeted TOTOLINK attack surface, so keep exposed devices off the public internet.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (the only version named in the available data; scope across other firmware versions not specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getCloudDownloadStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware download state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.