CVE-2026-51664: TOTOLINK T6 vulnerability
Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to obtain Telnet service enablement status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TOTOLINK T6to a version that resolves this vulnerability.Fixed in 4.1.5cu.748_B20211015 - Compensating control
Restrict network access to Telnet (port/service) so unauthenticated attackers cannot access Telnet service enablement status information exposed via /cgi-bin/cstecgi.cgi on TOTOLINK T6.
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker who can send a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint can obtain the Telnet service enablement status.
What information is exposed?
The affected getTelnetCfg function exposes whether the Telnet service is enabled. The provided data does not indicate that this issue enables changing the Telnet configuration or obtaining Telnet credentials.
Which product version is identified as affected?
The reported affected product is TOTOLINK T6 version 4.1.5cu.748_B20211015.