Junglewise Threat Intelligence

CVE-2026-51659: TOTOLINK T6 authentication bypass in getUrlFilterRules

CVE-2026-51659 · Severity: high · CVSS 7.5 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a residential router that manages network traffic filtering and security settings. An unauthenticated attacker can access the device's DMZ (demilitarized zone) configuration through a web interface flaw, allowing them to learn sensitive network topology information without logging in. This could enable follow-up attacks on exposed systems or network reconnaissance.

Technical details

The vulnerability is an authentication bypass in the getUrlFilterRules function of cstecgi.cgi on TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to retrieve DMZ configuration information that should require administrative authentication. The attack is remotely exploitable without user interaction via the network-accessible web management interface. No patch availability is currently indicated in the advisory.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References