Junglewise Threat Intelligence

CVE-2026-51635: TOTOLINK T6 missing authentication in getWiFiScheduleCfg

CVE-2026-51635 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a home router that manages Wi-Fi network settings and scheduling. An unauthenticated attacker on the network can retrieve sensitive Wi-Fi scheduling configuration by sending a crafted request, potentially exposing network policies and rules without requiring any credentials.

Technical details

The vulnerability exists in the getWiFiScheduleCfg function within the web-accessible cstecgi.cgi endpoint, which fails to enforce authentication checks. An attacker can send a POST request to /cgi-bin/cstecgi.cgi without credentials to retrieve Wi-Fi scheduling rules and configuration. This is a missing access control vulnerability (CWE-306) affecting an information disclosure function. No authentication is required and the endpoint is network-accessible, allowing any remote user to exploit this. A patch status is not indicated in the advisory.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References