Junglewise Threat Intelligence

CVE-2026-51672: TOTOLINK T6 authentication bypass in getRoamingCfg function

CVE-2026-51672 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a wireless router that manages network connectivity and configuration. An unauthenticated remote attacker can access the roaming enablement flag by sending a specially crafted request to the router's web interface, allowing them to read sensitive configuration settings without credentials. This undermines the device's security posture and exposes network configuration details to any attacker on the network.

Technical details

This vulnerability is an authentication bypass in the getRoamingCfg function of the cstecgi.cgi web interface handler in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The vulnerable function does not enforce authentication checks before processing requests, allowing unauthenticated attackers to retrieve the roaming configuration flag via a crafted POST request. The attack requires only network access to the device's web interface endpoint (/cgi-bin/cstecgi.cgi) and no user interaction. An attacker can extract sensitive configuration data that may be used for further reconnaissance or as a stepping stone to more severe attacks. No patch information is currently available from the advisory.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References