Junglewise Threat Intelligence

CVE-2026-51664: TOTOLINK T6 missing authentication in getTelnetCfg

CVE-2026-51664 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a consumer WiFi router that manages network connectivity and device access control. An unauthenticated attacker can query the router's Telnet service configuration status through a crafted web request, potentially identifying when Telnet is enabled and using that information for further compromise of the device's management interface.

Technical details

The getTelnetCfg function in cstecgi.cgi lacks proper authentication checks, allowing an unauthenticated POST request to /cgi-bin/cstecgi.cgi to retrieve Telnet enablement status. The vulnerable function is reachable over the network without credentials. While the information disclosed is limited to service status, it can serve as reconnaissance for attacks targeting the Telnet service itself or as part of a multi-stage compromise. A patch addressing this authentication bypass has been disclosed but adoption status is unknown.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References