Junglewise Threat Intelligence

CVE-2026-51629: TOTOLINK T6 missing authentication in getStaticDhcpRules

CVE-2026-51629 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a home router device that manages network settings and DHCP (Dynamic Host Configuration Protocol) reservations. An unauthenticated attacker can send a specially crafted request to retrieve sensitive static DHCP reservation rules, which may include device IP assignments and network configuration details. This allows an attacker to gather information about the network structure without needing administrator credentials.

Technical details

The getStaticDhcpRules function in the cstecgi.cgi CGI script on TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 lacks authentication checks, allowing unauthenticated attackers to access static DHCP reservation configuration. An attacker can send an unauthenticated POST request to /cgi-bin/cstecgi.cgi with the getStaticDhcpRules function parameter to retrieve DHCP reservation rules. This is a broken access control vulnerability affecting an information disclosure function. No authentication bypass or exploitation complexity is required—the function is directly callable over the network. A patch status has not been publicly disclosed.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References