Junglewise Threat Intelligence

CVE-2026-51656: TOTOLINK T6 getVpnPassCfg access control bypass

CVE-2026-51656 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a residential router used to provide network connectivity and security. An authentication bypass vulnerability in its web interface allows unauthenticated attackers to retrieve sensitive VPN pass-through and WAN ping filter settings by sending a crafted request, potentially enabling network reconnaissance or unauthorized configuration changes.

Technical details

The vulnerability is an authentication bypass (CWE-306) in the getVpnPassCfg function within the /cgi-bin/cstecgi.cgi endpoint of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The affected CGI handler fails to perform authentication checks before processing requests, allowing any unauthenticated remote attacker to send a POST request and retrieve VPN passthrough configuration and WAN ping filter settings. The attack requires only network reachability to the router's web interface and no user interaction. This is part of a broader pattern of authentication bypass vulnerabilities in this firmware version affecting multiple CGI functions.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References