CVE-2026-51671
TOTOLINK · T6
An incorrect access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to retrieve sensitive cloud firmware download status information via crafted POST requests.
Executive summary
A high-severity access control vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to leak internal system information.
Vulnerability
The vulnerability exists in the getCloudDownloadStatus function, which fails to enforce proper authentication checks. An unauthenticated attacker can exploit this by sending a specifically crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to extract firmware status data.
Business impact
Successful exploitation of this vulnerability results in the unauthorized disclosure of sensitive system information, which could facilitate further reconnaissance against the device. With a CVSS score of 7.5, this high-severity flaw poses a risk of information leakage that may compromise the security posture of the network environment in which the router is deployed.
Remediation
Immediate Action: Review the TOTOLINK support portal for the latest firmware release and apply it to all affected T6 devices immediately. If no patch is available, disable remote management features and restrict access to the web interface to trusted internal segments only.
Proactive Monitoring: Monitor network traffic logs for suspicious POST requests directed at /cgi-bin/cstecgi.cgi from untrusted or external IP addresses.
Compensating Controls: Deploy a Web Application Firewall (WAF) or an intrusion detection system to block or alert on unauthorized requests to the /cgi-bin/cstecgi.cgi endpoint.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high-severity nature of this information disclosure vulnerability, administrators should prioritize the identification of all vulnerable TOTOLINK T6 units within their infrastructure. Apply vendor-supplied patches as soon as they become available and implement network-level access controls to limit exposure to the administrative web interface.