Junglewise Threat Intelligence

CVE-2026-51663: TOTOLINK T6 authentication bypass in getWiFiApcliScan

CVE-2026-51663 · Severity: critical · CVSS 9.8 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

The TOTOLINK T6 wireless router contains an access control flaw that allows unauthenticated attackers to trigger WiFi network scans and retrieve sensitive AP-client scan results. An attacker can exploit this by sending a crafted web request to the device's administration interface without providing valid credentials, potentially exposing network topology and connected device information.

Technical details

An authentication bypass vulnerability exists in the getWiFiApcliScan function of the device's web administration CGI interface (/cgi-bin/cstecgi.cgi). The vulnerability is due to missing authentication checks on a sensitive endpoint that should require administrator credentials. An attacker on the network can send an unauthenticated POST request to trigger wireless scans and retrieve detailed AP-client scan results. No user interaction is required; the flaw is directly exploitable via network access to the device's web interface. A fix or patch availability is not indicated in the advisory.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References