CVE-2026-51672: TOTOLINK T6 vulnerability
Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to obtain the roaming enablement flag via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TOTOLINK T6to a version that resolves this vulnerability.Fixed in 4.1.5cu.748_B20211015
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
The affected product identified in the available data is TOTOLINK T6 running firmware version 4.1.5cu.748_B20211015. The issue is reachable through the device's CGI endpoint.
Does an attacker need to authenticate first?
No. An unauthenticated attacker can obtain the roaming enablement flag by sending a crafted POST request to /cgi-bin/cstecgi.cgi.
What information can be exposed?
The disclosed information is the device's roaming enablement flag. The provided data does not indicate exposure of other configuration values or credentials.