CVE-2026-51617

TOTOLINK · T6

A vulnerability in the getSysStatusCfg function of TOTOLINK T6 allows unauthenticated attackers to retrieve sensitive system and network configuration data via a crafted POST request.

Executive summary

A high-severity information disclosure vulnerability in the TOTOLINK T6 router permits unauthenticated attackers to access sensitive credentials and network configuration details.

Vulnerability

This flaw involves incorrect access control within the getSysStatusCfg function. An unauthenticated attacker can exploit this by sending a specifically crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to extract sensitive information, including encryption keys and network topology data.

Business impact

The exposure of sensitive information, such as WiFi encryption keys and WAN/LAN IP addresses, significantly undermines the security of the internal network. This vulnerability carries a CVSS score of 7.5, reflecting a high risk of unauthorized data access that could facilitate further lateral movement or unauthorized network entry, potentially leading to widespread compromise of connected devices.

Remediation

Immediate Action: Consult the official TOTOLINK support portal to determine if a firmware update addressing this vulnerability is available for your specific hardware revision.

Proactive Monitoring: Monitor network traffic for anomalous POST requests directed at the /cgi-bin/cstecgi.cgi endpoint, which may indicate attempted exploitation.

Compensating Controls: Restrict administrative management access to the router to trusted internal interfaces only, and ensure the device is not reachable from the public internet.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the sensitive nature of the exposed data, organizations using the TOTOLINK T6 must prioritize mitigating this risk. If a vendor-supplied patch is not yet available, administrators should immediately isolate the device from external network access to prevent unauthenticated exploitation attempts.

More TOTOLINK CVEs

Sources