Junglewise Threat Intelligence

CVE-2026-51638: TOTOLINK T6 access control bypass in getWiFiGuestCfg

CVE-2026-51638 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

The TOTOLINK T6 router contains an authentication bypass vulnerability in its web management interface that allows an unauthenticated attacker to retrieve guest Wi-Fi network configuration details by sending a specially crafted request. This could enable an attacker to discover guest network credentials or settings without logging into the device, potentially allowing unauthorized access to the guest network and a foothold for further network compromise.

Technical details

The vulnerability is an authentication bypass in the getWiFiGuestCfg function of the cstecgi.cgi CGI script on TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi without credentials to retrieve guest Wi-Fi configuration information. The root cause is missing or incorrect access control validation on this configuration retrieval function. No authentication or authorization check is performed before returning sensitive Wi-Fi guest network settings. Patches or updates to address this vulnerability are not explicitly mentioned in the available documentation.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References