Junglewise Threat Intelligence

CVE-2026-51633: TOTOLINK T6 incorrect access control in getWiFiEasyGuestCfg

CVE-2026-51633 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

The TOTOLINK T6 router's guest Wi-Fi configuration function lacks proper authentication controls, allowing unauthenticated attackers to retrieve guest network credentials and settings. An attacker on the network can issue a simple web request to extract sensitive Wi-Fi access information, potentially enabling unauthorized access to the guest network and internal network reconnaissance.

Technical details

The getWiFiEasyGuestCfg function in the cstecgi.cgi endpoint of TOTOLINK T6 firmware 4.1.5cu.748_B20211015 is missing authentication checks before processing requests. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to retrieve guest Wi-Fi configuration data, including SSID, encryption type, and pre-shared keys. The vulnerability requires only network reachability to the web interface (typically accessible via HTTP/HTTPS on the LAN) and no user interaction. This allows information disclosure of guest network credentials, which could facilitate unauthorized network access.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References