CVE-2026-51735
TOTOLINK · T6
A flaw in the showSyslog function of TOTOLINK T6 allows unauthenticated attackers to retrieve sensitive system logs via a crafted POST request.
Executive summary
An unauthenticated access control vulnerability in the TOTOLINK T6 router allows remote attackers to exfiltrate system logs, potentially exposing sensitive network information.
Vulnerability
The device fails to perform proper access control checks within the showSyslog function, which can be reached by sending a malicious POST request to the cgi-bin-cstecgi.cgi endpoint. This vulnerability allows an unauthenticated remote attacker to gain unauthorized access to internal system logs.
Business impact
The successful exploitation of this vulnerability results in the unauthorized disclosure of system logs, which may contain sensitive information such as network configurations, connected device details, or authentication artifacts. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to organizational privacy and network security, as it facilitates reconnaissance for further lateral movement or targeted attacks.
Remediation
Immediate Action: Contact TOTOLINK support or check the official product support page to determine if a firmware update is available for your specific hardware revision. If no patch is currently available, restrict access to the web management interface to trusted internal networks only.
Proactive Monitoring: Review system logs for unusual POST requests directed at the cgi-bin-cstecgi.cgi endpoint or high volumes of traffic originating from unauthorized external IP addresses.
Compensating Controls: Implement strict firewall rules to block external access to the device management interface, effectively isolating the vulnerable function from the public internet.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a significant security oversight that exposes internal operational data to the public internet. Organizations currently utilizing TOTOLINK T6 hardware should treat this as a priority item, ensuring that the web management interface is strictly sequestered from external access until a vendor-supplied security update is applied.