Junglewise Threat Intelligence

CVE-2026-51651: TOTOLINK T6 missing authentication in getSmartQosCfg

CVE-2026-51651 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

The TOTOLINK T6 router allows unauthenticated remote attackers to retrieve sensitive Smart QoS (Quality of Service) configuration and traffic management rules by sending a crafted web request. An attacker could discover network policies, traffic prioritization settings, and device management configurations without needing admin credentials, potentially enabling network reconnaissance or policy manipulation.

Technical details

This vulnerability is a missing authentication / improper access control issue in the getSmartQosCfg function of the cstecgi.cgi web interface. An unauthenticated attacker can send a POST request to /cgi-bin/cstecgi.cgi and retrieve Smart QoS configuration data that should be restricted to authenticated administrators. The vulnerability requires only network access to the router's web interface (typically TCP 80/443) and no user interaction. The attacker gains read access to QoS settings and rules, which could facilitate network analysis or facilitate further reconnaissance. Patch availability is not indicated in the advisory.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References