Junglewise Threat Intelligence

CVE-2026-51620: TOTOLINK T6 getNetInfoCfg authentication bypass

CVE-2026-51620 · Severity: high · CVSS 7.5 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

The TOTOLINK T6 router's web management interface contains a missing authentication control that allows unauthenticated attackers to access network topology and interface configuration details. An attacker can send a crafted request to the router to retrieve sensitive network information without logging in, potentially enabling reconnaissance for further attacks or network mapping for malicious purposes.

Technical details

The getNetInfoCfg function in the cstecgi.cgi endpoint of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 lacks proper authentication validation. An unauthenticated attacker can send a POST request to /cgi-bin/cstecgi.cgi with the getNetInfoCfg function call to retrieve network configuration data including interface details and topology information. The vulnerability requires only network access to the router's management interface and no user interaction. This is a missing authentication issue (CWE-306) that exposes sensitive configuration details useful for network reconnaissance and planning of further attacks.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References