Junglewise Threat Intelligence

CVE-2026-51624: TOTOLINK T6 missing authentication in getStationMacByIp

CVE-2026-51624 · Severity: high · CVSS 7.5 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a wireless router used to provide internet connectivity to homes and offices. An unauthenticated attacker can obtain the MAC address of connected WiFi clients by sending a specially crafted request to the router's web interface, enabling device enumeration and network reconnaissance without any credentials.

Technical details

The getStationMacByIp function in the cstecgi.cgi CGI script lacks proper authentication checks, allowing unauthenticated POST requests to retrieve client MAC addresses. The vulnerability exists in the web management interface accessible at /cgi-bin/cstecgi.cgi. An attacker on the network can send a crafted POST request to extract MAC address information for any connected client, facilitating network mapping and targeted attacks. No authentication or special privileges are required to exploit this vulnerability.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References