Junglewise Threat Intelligence

CVE-2026-51645: TOTOLINK T6 authentication bypass in getPasswordCfg

CVE-2026-51645 · Severity: critical · CVSS 9.8 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a wireless router used to provide internet connectivity in homes and small offices. An unauthenticated attacker can bypass access controls and obtain the administrative username by sending a specially crafted request to the router's web interface, enabling full administrative takeover without a valid password.

Technical details

The vulnerability is an authentication bypass (missing access control) in the getPasswordCfg function within the cstecgi.cgi CGI script on TOTOLINK T6 routers. An unauthenticated remote attacker can send a POST request to /cgi-bin/cstecgi.cgi to retrieve the administrative username. No prior authentication or credentials are required; the vulnerability is network-reachable from any network segment that can communicate with the router. Successful exploitation allows an attacker to obtain the admin username and, combined with weak password defaults or other vulnerabilities in the same firmware, could lead to full device compromise. A patch for firmware version 4.1.5cu.748_B20211015 has not been indicated as available at this time.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References