ZeroHour

CVE-2026-51672

moderate

Unauthenticated information disclosure in TOTOLINK T6 router (getRoamingCfg)

CVSS 3.1
9.1 critical
EPSS
<1%p30
Published
()
Modified
AI analysis

TOTOLINK T6 router firmware 4.1.5cu.748_B20211015 contains an incorrect access control flaw (CWE-284) in the getRoamingCfg function of its web management interface. An unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi, invoking getRoamingCfg without any credentials. The attacker gains disclosure of the device's roaming enablement flag; the flaw is scored 9.1 (critical) in CVSS 3.1, reflecting network exploitability with no privileges or user interaction required. Anyone running the listed T6 firmware is affected, especially where the management interface is reachable from the WAN; other versions may be affected but are not confirmed in the available data. No public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS assigns roughly a 0.4% probability of exploitation within 30 days, so no exploitation is currently known.

What to do: Check T6 units for firmware 4.1.5cu.748_B20211015 and do not expose the web management interface (cstecgi.cgi) to the WAN or untrusted networks until TOTOLINK publishes a fixed release; no fixed version is identified in the available data, so monitor the vendor for an update. As interim mitigation, restrict administrative access to trusted LAN hosts and watch for unauthenticated POST requests to /cgi-bin/cstecgi.cgi invoking getRoamingCfg.

Affected
TOTOLINK T64.1.5cu.748_B20211015
Estimated exposure
moderate≈1,000–10,000 exposed devices plausibly affected (single consumer model; TOTOLINK line appears in public internet scans in the tens of thousands across models)… — TOTOLINK consumer routers regularly appear in internet-wide scans in the tens of thousands across the product line, and the T6 is a single model within that line, so the number of units with a WAN-reachable management interface is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the roaming enablement flag via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.