Junglewise Threat Intelligence

CVE-2026-51655: TOTOLINK T6 getMacFilterRules missing authentication

CVE-2026-51655 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a wireless router used in home and small office networks. An unauthenticated attacker can remotely retrieve MAC address filter rules by sending a crafted request to the router's web interface, potentially exposing network security policies and enabling further targeted attacks against connected devices.

Technical details

The getMacFilterRules function in TOTOLINK T6's cstecgi.cgi web interface lacks proper authentication checks, allowing unauthenticated remote attackers to retrieve MAC filter rules via a crafted POST request. This is an access control bypass vulnerability where sensitive configuration information is exposed without requiring valid credentials. The vulnerability is network-accessible and requires no user interaction or authentication, only the ability to send HTTP POST requests to the affected router. An attacker can leverage this information disclosure to understand the network's security posture and identify which devices are whitelisted or blacklisted, potentially informing further attacks. The advisory does not specify if a patch is available.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References