Junglewise Threat Intelligence

CVE-2026-51636: TOTOLINK T6 getWiFiAclRules authentication bypass

CVE-2026-51636 · Severity: critical · CVSS 9.1 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

The TOTOLINK T6 router's Wi-Fi access control management function lacks proper authentication checks, allowing unauthenticated attackers to retrieve sensitive Wi-Fi ACL (access control list) rules and network configuration details. An attacker on the network can craft a simple HTTP request to extract these rules without logging in, potentially revealing network security policies and enabling further attacks against connected devices.

Technical details

This is an authentication bypass vulnerability in the getWiFiAclRules CGI function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The vulnerable endpoint at /cgi-bin/cstecgi.cgi fails to validate user credentials before processing requests for Wi-Fi ACL configuration data. An attacker with network access can send an unauthenticated POST request to retrieve sensitive Wi-Fi security rules. The vulnerability allows complete disclosure of Wi-Fi access control configuration without any authentication requirement. A patch may be available through vendor firmware updates, though the advisory does not explicitly confirm patch status.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References