CVE-2026-51658

TOTOLINK · T6

An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to retrieve DMZ configuration details via a crafted POST request.

Executive summary

A critical access control flaw in the TOTOLINK T6 router allows unauthenticated attackers to exfiltrate sensitive DMZ configuration data, posing a significant risk to network security.

Vulnerability

This vulnerability resides in the getDmzCfg function within the device firmware. It allows an unauthenticated attacker to bypass security checks and access sensitive configuration information by sending a specifically crafted POST request to the /cgi-bin/cstecgi.cgi endpoint.

Business impact

The exposure of DMZ configuration details provides an attacker with critical intelligence regarding the internal network structure and exposed services. Given the CVSS score of 7.5, this high severity vulnerability could facilitate further targeted attacks against internal assets, leading to unauthorized access, potential data breaches, and significant compromise of the network perimeter.

Remediation

Immediate Action: Review the official TOTOLINK support portal for firmware updates addressing this specific vulnerability and apply them immediately if available.

Proactive Monitoring: Monitor network traffic for suspicious or malformed POST requests directed at the /cgi-bin/cstecgi.cgi endpoint, which may indicate reconnaissance or exploitation attempts.

Compensating Controls: If no patch is available, restrict management interface access to trusted administrative IP addresses only and ensure the device is not directly exposed to the public internet.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The ability for an unauthenticated user to extract configuration data from a network device is a severe security failure. Organizations utilizing the TOTOLINK T6 hardware should prioritize securing the management interface and verify the availability of firmware updates to mitigate the risk of unauthorized information disclosure.

More TOTOLINK CVEs

Sources