Junglewise Threat Intelligence

CVE-2026-51613: TOTOLINK T6 authentication bypass in getDeviceInfo

CVE-2026-51613 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

The TOTOLINK T6 router's web management interface lacks authentication checks on a function that exposes device identification details. An attacker on the network can retrieve sensitive information such as device hardware identifiers and configuration metadata without logging in, potentially enabling further attacks or reconnaissance.

Technical details

The getDeviceInfo function in the cstecgi.cgi script fails to validate user authentication before returning device information. An unauthenticated attacker can craft a POST request to /cgi-bin/cstecgi.cgi with the appropriate parameters to invoke getDeviceInfo and retrieve sensitive device data. This is an access control vulnerability (missing authentication check) accessible to any network-reachable host. The vulnerability allows information disclosure that could support further exploitation attacks. No patch information is currently available.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References