Junglewise Threat Intelligence

CVE-2026-51658: TOTOLINK T6 auth bypass in getDmzCfg

CVE-2026-51658 · Severity: high · CVSS 7.5 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a residential router used to provide Internet connectivity and network management. An unauthenticated remote attacker can retrieve sensitive DMZ configuration settings by sending a specially crafted request, potentially exposing internal network architecture and exposing systems behind the DMZ.

Technical details

This is an authentication bypass vulnerability in the getDmzCfg function within the cstecgi.cgi CGI script on TOTOLINK T6 routers. The vulnerable function fails to validate authentication before returning DMZ configuration information. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi with the getDmzCfg parameter to retrieve sensitive configuration data without any credentials. The attack requires only network access to the router's web interface and does not require user interaction. No patch availability information is currently known.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References