CVE-2026-51650

TOTOLINK · T6

An incorrect access control vulnerability in the TOTOLINK T6 getRemoteCfg function allows unauthenticated attackers to retrieve remote management and port information via a crafted POST request.

Executive summary

A high-severity access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to extract sensitive configuration details, potentially facilitating further network attacks.

Vulnerability

The flaw resides in the getRemoteCfg function within the /cgi-bin/cstecgi.cgi endpoint. It lacks proper authentication checks, enabling an unauthenticated remote attacker to gain unauthorized access to critical device management configurations.

Business impact

The exposure of remote management settings and port information provides attackers with a roadmap for further unauthorized access to the network. Given the CVSS score of 7.5, this vulnerability represents a significant risk to organizational perimeter security, as it facilitates reconnaissance and potential lateral movement into internal systems.

Remediation

Immediate Action: Review the vendor advisory at the official TOTOLINK support page to determine if a firmware update is available for your specific device build and apply it immediately.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at /cgi-bin/cstecgi.cgi and inspect logs for unauthorized attempts to access remote management configurations.

Compensating Controls: Disable remote management interfaces on the WAN side of the router if they are not strictly required for business operations. Use a Web Application Firewall or network access control list to restrict access to the administrative interface to trusted internal IP addresses only.

Exploitation status

Public Exploit Available: No (There is no confirmed public exploit or weaponized code available in the provided data).

Analyst recommendation

This vulnerability presents a clear risk to device integrity and network visibility. Administrators must verify the firmware version of all deployed TOTOLINK T6 units against the vendor provided list and apply patches as soon as they are released. Until a patch is confirmed and deployed, restrict management access to the device to prevent remote exploitation.

More TOTOLINK CVEs

Sources