Executive brief
TOTOLINK T6 is a home or small-office router that provides network connectivity and administration capabilities. An unauthenticated attacker can send a crafted web request to expose WAN-side (internet-facing) administration settings, potentially allowing unauthorized remote access to router management interfaces and full network compromise.
Technical details
The vulnerability is an authentication bypass and information disclosure flaw in the setRemoteCfg function within the web CGI interface (/cgi-bin/cstecgi.cgi). The vulnerable endpoint fails to validate authentication before processing POST requests, allowing an unauthenticated attacker to retrieve sensitive configuration data related to WAN administration. The attack requires network reachability to the router's web interface (typically port 80 or 443) but no prior credentials. Successful exploitation exposes configuration details that could facilitate further attacks, including remote management access and network infiltration. A patch status is not mentioned in the advisory.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed
- 2026-08-31: advisory: CVE-2026-51681 published on NVD