Junglewise Threat Intelligence

CVE-2026-51622: TOTOLINK T6 missing authentication in getWanCfg function

CVE-2026-51622 · Severity: critical · CVSS 9.1 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a wireless router used in home and small business networks to provide internet connectivity and WiFi access. An unauthenticated remote attacker can retrieve sensitive WAN (wide-area network) configuration data by sending a crafted request to the device's web interface, potentially exposing ISP credentials, connection details, and network setup information without requiring a password.

Technical details

The vulnerability is an authentication bypass in the cstecgi.cgi web interface, specifically in the getWanCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The affected function fails to validate user authentication before processing requests for WAN configuration data, allowing unauthenticated attackers to retrieve sensitive network settings via POST requests to /cgi-bin/cstecgi.cgi. No authentication credentials are required to exploit this vulnerability. An attacker can obtain WAN configuration details from any network position with access to the router's web interface. A patch or firmware update addressing this authentication bypass has not been confirmed in the provided information.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References