Junglewise Threat Intelligence

CVE-2026-51653: TOTOLINK T6 missing authentication in getStorageCfg function

CVE-2026-51653 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a residential router/gateway device used to provide network connectivity and storage management features. An unauthenticated attacker on the network can query the device's storage configuration settings via a crafted POST request, exposing internal system state that should remain private.

Technical details

This vulnerability is a missing authentication (incorrect access control) issue in the getStorageCfg function within the cstecgi.cgi web interface of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An attacker can send a specially crafted POST request to /cgi-bin/cstecgi.cgi to retrieve storage feature state information without providing authentication credentials. The attack requires only network access to the device's web interface; no user interaction is needed. While not remotely exploitable from the internet in most home networks (due to NAT), it poses a risk in environments where the device is directly exposed or accessible via local network. No patch status is available in the advisory text.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References