Junglewise Threat Intelligence

CVE-2026-51648: TOTOLINK T6 authentication bypass in getWanInfo

CVE-2026-51648 · Severity: high · CVSS 7.5 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a wireless router used to provide network connectivity. An authentication bypass vulnerability in the router's web interface allows unauthenticated remote attackers to access sensitive WAN (Wide Area Network) configuration information by sending a crafted request. This exposure could reveal network topology and settings used by the router, facilitating further attacks on the network.

Technical details

The getWanInfo function in the cstecgi.cgi CGI script lacks proper access control checks, allowing unauthenticated attackers to retrieve WAN configuration details via a POST request to /cgi-bin/cstecgi.cgi. The vulnerability stems from missing authentication validation on this sensitive administrative function. The attack requires only network access to the router's web interface; no credentials or special preconditions are required. An unauthenticated attacker can call this function remotely to obtain WAN information that should be restricted to authenticated administrators. Patching status is not specified in the advisory.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References