Junglewise Threat Intelligence

CVE-2026-51621: TOTOLINK T6 missing authentication in getInitCfg

CVE-2026-51621 · Severity: high · CVSS 7.5 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a network access device used in ISP and enterprise deployments. An unauthenticated attacker can retrieve sensitive device configuration information by sending a crafted request to the web interface, potentially exposing network settings, WiFi credentials, and system details that could enable further attacks.

Technical details

The getInitCfg function in the cstecgi.cgi web interface lacks proper authentication checks, allowing unauthenticated POST requests to retrieve sensitive device configuration data. The vulnerability exists in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An attacker on the network (or with network access to the device's web interface) can exploit this via a simple POST request to /cgi-bin/cstecgi.cgi without credentials, obtaining initialization configuration including WiFi settings, network parameters, and system information. No patch information is currently available in the advisory.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References