CVE-2026-51617: TOTOLINK T6 vulnerability
Incorrect access control in the getSysStatusCfg function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to obtain sensitive information such as operation mode, firmware version, serial number, WAN/LAN IP addresses, WiFi SSID, encryption keys, and connected client statistics via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker can exploit it, so no valid router login is required. Any attacker able to send a crafted POST request to the device's CGI endpoint is exposed to this access-control failure.
What information could be disclosed?
The affected function can expose the operation mode, firmware version, serial number, WAN and LAN IP addresses, WiFi SSID, encryption keys, and connected-client statistics.
How can I check whether a device is affected?
Confirm that the device is a TOTOLINK T6 running firmware 4.1.5cu.748_B20211015. The issue concerns unauthenticated access to getSysStatusCfg through /cgi-bin/cstecgi.cgi.