CVE-2026-51629: TOTOLINK T6 vulnerability
Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to obtain static DHCP reservation rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
The affected product identified in the available data is TOTOLINK T6 running firmware 4.1.5cu.748_B20211015. Exposure requires that an attacker can send requests to the device's web management CGI endpoint.
Does exploitation require authentication?
No. The issue allows unauthenticated attackers to retrieve static DHCP reservation rules by sending a crafted POST request to /cgi-bin/cstecgi.cgi.
What information could an attacker obtain?
An attacker can obtain static DHCP reservation rules through the getStaticDhcpRules function. The available data does not specify whether other configuration data or administrative actions are accessible.