Junglewise Threat Intelligence

CVE-2026-51657: TOTOLINK T6 auth bypass in getSyslogCfg

CVE-2026-51657 · Severity: critical · CVSS 9.1 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a home/small-business WiFi router that stores operational logs and system settings. This vulnerability allows an unauthenticated attacker on the network to retrieve sensitive syslog configuration details by sending a single web request, potentially exposing diagnostic information and system settings that should be restricted to authorized administrators.

Technical details

The vulnerability is an authentication bypass in the getSyslogCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The vulnerable CGI endpoint /cgi-bin/cstecgi.cgi fails to properly validate user credentials before processing requests for syslog configuration. An unauthenticated attacker on the network can craft a POST request to this endpoint to retrieve syslog-related configuration without providing valid login credentials. No CVSS vector details are available in the advisory, though the reported CVSS score is 9.1 (critical). A patch status is not mentioned in the provided materials.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References