CVE-2026-51735
—Unauthenticated access-control flaw in TOTOLINK T6 exposes system logs
CVE-2026-51735 is an incorrect access-control issue (CWE-284) in the showSyslog function of TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An unauthenticated remote attacker can send a crafted POST request to the device's /cgi-bin/cstecgi.cgi endpoint to invoke showSyslog and retrieve the router's recent system logs without logging in. The impact is confidentiality-only (CVSS 3.1: 7.5 High, C:H/I:N/A:N), meaning the attacker reads sensitive log content that may reveal device and network activity, but cannot alter configuration or disrupt the device. Only TOTOLINK T6 routers running the cited firmware build are identified as affected in the MITRE-assigned record. Exploitation is not currently reported: no public proof-of-concept exists, the CVE is not in CISA KEV, and EPSS estimates only a ~0.4% probability of exploitation within 30 days (30th percentile).
What to do: Update the T6 to a firmware release newer than 4.1.5cu.748_B20211015 when TOTOLINK publishes a fix (no fixed build is cited in the record), and check your current firmware version on affected units. Until patching, avoid exposing the router's web management interface (cstecgi.cgi) to the WAN or untrusted networks, and restrict admin access to trusted LAN/VPN clients. Given the confidentiality-only impact and low EPSS, this is lower urgency, but treat any exposed devices as candidates for log-content review.
| TOTOLINK T6 (router) | 4.1.5cu.748_B20211015 (the only firmware build cited; scope of other builds not specified in the record) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve recent system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.