CVE-2026-51672
moderateUnauthenticated information disclosure in TOTOLINK T6 router (getRoamingCfg)
TOTOLINK T6 router firmware 4.1.5cu.748_B20211015 contains an incorrect access control flaw (CWE-284) in the getRoamingCfg function of its web management interface. An unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi, invoking getRoamingCfg without any credentials. The attacker gains disclosure of the device's roaming enablement flag; the flaw is scored 9.1 (critical) in CVSS 3.1, reflecting network exploitability with no privileges or user interaction required. Anyone running the listed T6 firmware is affected, especially where the management interface is reachable from the WAN; other versions may be affected but are not confirmed in the available data. No public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS assigns roughly a 0.4% probability of exploitation within 30 days, so no exploitation is currently known.
What to do: Check T6 units for firmware 4.1.5cu.748_B20211015 and do not expose the web management interface (cstecgi.cgi) to the WAN or untrusted networks until TOTOLINK publishes a fixed release; no fixed version is identified in the available data, so monitor the vendor for an update. As interim mitigation, restrict administrative access to trusted LAN hosts and watch for unauthenticated POST requests to /cgi-bin/cstecgi.cgi invoking getRoamingCfg.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the roaming enablement flag via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.