Junglewise Threat Intelligence

CVE-2026-51650: TOTOLINK T6 auth bypass in getRemoteCfg

CVE-2026-51650 · Severity: high · CVSS 7.5 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a residential WiFi router used for home internet access and network management. An unauthenticated attacker can send a crafted web request to discover whether remote management is enabled and what port it uses, potentially facilitating unauthorized access to the device's administration interface.

Technical details

The vulnerability is an authentication bypass (missing access control) in the getRemoteCfg function of the cstecgi.cgi CGI script. The affected versions fail to validate user authentication before processing requests to retrieve remote-management configuration. An attacker on the network can send an unauthenticated POST request to /cgi-bin/cstecgi.cgi with the getRemoteCfg parameter to obtain sensitive configuration details including whether remote management is enabled and the listening port. No user interaction is required. The attack vector is network-adjacent (LAN access typically required for home routers).

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References