CVE-2026-51636: TOTOLINK T6 vulnerability
Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to obtain Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker who can send a crafted POST request to the device's web interface can retrieve Wi-Fi ACL rules. The provided data does not state that prior credentials or administrative access are required.
What information can be exposed?
The issue allows retrieval of Wi-Fi ACL rules through the getWiFiAclRules function. The provided data does not specify the exact fields or entries contained in those rules.
Which firmware version is identified as affected?
The affected version identified is TOTOLINK T6 firmware 4.1.5cu.748_B20211015.
How can I determine whether a device is vulnerable?
A device is identified as affected if it is a TOTOLINK T6 running firmware 4.1.5cu.748_B20211015. The supplied information does not provide a patched version or an alternative detection method.