Junglewise Threat Intelligence

CVE-2026-51625: TOTOLINK T6 missing authentication in getWiFiEasyCfg

CVE-2026-51625 · Severity: high · CVSS 7.5 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 routers are consumer WiFi devices used in home networks. An unauthenticated attacker on the network can retrieve the wireless network name (SSID) and password by sending a simple web request, allowing them to connect to the WiFi or compromise the router's security configuration.

Technical details

The getWiFiEasyCfg function in the cstecgi.cgi CGI script fails to enforce authentication checks before returning sensitive WiFi configuration data. An attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi with the getWiFiEasyCfg function call without providing valid credentials, and receive the SSID and WiFi pre-shared key (PSK) in the response. No authentication is required and the request is network-reachable; exploitation requires only network access to the router's web interface. This disclosure of sensitive WiFi credentials undermines network security and allows unauthorized access to the wireless network.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References