Junglewise Threat Intelligence

CVE-2026-51614: TOTOLINK T6 missing authentication in getAccessDeviceCfg

CVE-2026-51614 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a wireless router used for home and small business networking. The device's configuration interface contains a flaw that allows attackers on the network to retrieve sensitive access-device policies and connected client information without providing login credentials, potentially enabling network reconnaissance and unauthorized access planning.

Technical details

The getAccessDeviceCfg function in the cstecgi.cgi CGI script fails to properly validate user authentication before processing requests. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to invoke this function and retrieve access-device policy configuration and client state information. No authentication is required and the function is network-accessible. This is an authentication bypass / missing access control vulnerability (CWE-306). Exploitation requires only network reachability to the device's web interface on the LAN.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References