Junglewise Threat Intelligence

CVE-2026-51634: TOTOLINK T6 unauthenticated access to wireless settings

CVE-2026-51634 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

The TOTOLINK T6 router exposes a configuration management interface that fails to verify user authentication, allowing anyone on the network to retrieve core Wi-Fi settings without a password. An attacker could obtain the network SSID and Wi-Fi encryption key (PSK), enabling them to connect to the network, intercept traffic, or launch further attacks on connected devices.

Technical details

This vulnerability is an authentication bypass in the getWiFiBasicCfg function within the cstecgi.cgi CGI script on TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The affected endpoint at /cgi-bin/cstecgi.cgi accepts unauthenticated POST requests and returns sensitive Wi-Fi configuration data including SSIDs and pre-shared keys. The attack requires only network reachability to the management interface (typically the router's web admin port, defaulting to port 80 or 8080) and does not require any prior authentication. An unauthenticated attacker can send a crafted POST request to retrieve complete wireless configuration without credentials, directly exposing network secrets.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References