CVE-2026-51615: TOTOLINK T6 vulnerability
Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated attacker able to reach the router’s web management CGI endpoint can request the exposed information. No login is required.
What information can be obtained?
The affected getLanCfg function can disclose LAN addressing and DHCP configuration information.
What request path is involved?
The issue is reached by sending a crafted POST request to /cgi-bin/cstecgi.cgi.
How can I determine whether my device is affected?
The identified affected product and firmware are TOTOLINK T6 running 4.1.5cu.748_B20211015. Testing should verify whether an unauthenticated crafted POST request to the specified CGI path returns LAN or DHCP configuration data.