Junglewise Threat Intelligence

CVE-2026-51617: TOTOLINK T6 authentication bypass in getSysStatusCfg

CVE-2026-51617 · Severity: high · CVSS 7.5 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

The TOTOLINK T6 router lacks proper authentication checks in its web management interface, allowing unauthenticated attackers to retrieve sensitive configuration details including firmware version, serial number, network IP addresses, WiFi credentials, and encryption keys. An attacker on the network can exploit this to gather intelligence for further attacks or to access WiFi networks.

Technical details

This is an authentication bypass vulnerability in the getSysStatusCfg function within the cstecgi.cgi web interface of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to retrieve sensitive system information without providing credentials. The vulnerable function fails to implement access control checks before returning configuration data. No authentication or special privileges are required; the vulnerability is remotely exploitable by any attacker with network access to the device. An exploit allows disclosure of operation mode, firmware version, serial number, WAN/LAN IP addresses, WiFi SSID, encryption keys, and connected client statistics. Patch status is not explicitly stated in available sources.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References