Junglewise Threat Intelligence

CVE-2026-51630: TOTOLINK T6 missing authentication in getDdnsCfg function

CVE-2026-51630 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a wireless router used in home and small business networks. An unauthenticated attacker on the network can access the router's web interface and retrieve DDNS configuration details, including the domain name, username, and password used to update dynamic DNS services. This allows an attacker to take control of the router's DNS configuration or compromise connected services.

Technical details

The getDdnsCfg function in the router's cstecgi.cgi web interface lacks authentication checks, allowing unauthenticated attackers to send a crafted POST request to /cgi-bin/cstecgi.cgi and retrieve sensitive DDNS configuration data including domain, username, and password. The vulnerability affects TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The attack requires network-level access to the router's web interface but no user interaction or credentials. An attacker can exploit this to extract DDNS credentials and reconfigure DNS settings, potentially redirecting traffic or disrupting service availability.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References