Junglewise Threat Intelligence

CVE-2026-51652: TOTOLINK T6 missing authentication in getUPnPCfg

CVE-2026-51652 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

The TOTOLINK T6 router's web administration interface contains an authentication bypass vulnerability in the UPnP configuration function. An unauthenticated attacker on the network can retrieve sensitive UPnP settings and port-mapping information without logging in, potentially enabling further network reconnaissance or exploitation.

Technical details

The getUPnPCfg function in the cstecgi.cgi CGI script fails to enforce authentication checks before returning UPnP configuration data. An attacker can craft a POST request to /cgi-bin/cstecgi.cgi with the getUPnPCfg parameter to extract UPnP enablement status and port-mapping information without credentials. The vulnerability requires network access to the router's web interface (typically port 80 or 443). No patch information is currently available for the affected firmware version 4.1.5cu.748_B20211015.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References