CVE-2026-51649: TOTOLINK T6 vulnerability
Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to obtain diagnostic configuration and ping log contents via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker can exploit it, so no valid router credentials are required. The attacker needs network access to the device's web management interface.
What information can be exposed?
The vulnerable getDiagnosisCfg function can disclose diagnostic configuration data and ping log contents when a crafted POST request is sent to /cgi-bin/cstecgi.cgi.
How can I determine whether my device is affected?
The reported affected product and firmware version are TOTOLINK T6 running 4.1.5cu.748_B20211015. Exposure also depends on whether an attacker can reach the device's web management interface.