CVE-2026-51658
TOTOLINK · T6
An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to retrieve DMZ configuration details via a crafted POST request.
Executive summary
A critical access control flaw in the TOTOLINK T6 router allows unauthenticated attackers to exfiltrate sensitive DMZ configuration data, posing a significant risk to network security.
Vulnerability
This vulnerability resides in the getDmzCfg function within the device firmware. It allows an unauthenticated attacker to bypass security checks and access sensitive configuration information by sending a specifically crafted POST request to the /cgi-bin/cstecgi.cgi endpoint.
Business impact
The exposure of DMZ configuration details provides an attacker with critical intelligence regarding the internal network structure and exposed services. Given the CVSS score of 7.5, this high severity vulnerability could facilitate further targeted attacks against internal assets, leading to unauthorized access, potential data breaches, and significant compromise of the network perimeter.
Remediation
Immediate Action: Review the official TOTOLINK support portal for firmware updates addressing this specific vulnerability and apply them immediately if available.
Proactive Monitoring: Monitor network traffic for suspicious or malformed POST requests directed at the /cgi-bin/cstecgi.cgi endpoint, which may indicate reconnaissance or exploitation attempts.
Compensating Controls: If no patch is available, restrict management interface access to trusted administrative IP addresses only and ensure the device is not directly exposed to the public internet.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The ability for an unauthenticated user to extract configuration data from a network device is a severe security failure. Organizations utilizing the TOTOLINK T6 hardware should prioritize securing the management interface and verify the availability of firmware updates to mitigate the risk of unauthorized information disclosure.