Description
Incorrect access control in the getDeviceInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain device identification details via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-28
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The getDeviceInfo function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an access‑control flaw. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and receive the device's identification data, such as serial number, firmware version and network identifiers. This enables information disclosure and can be employed as a foothold for subsequent targeted attacks on the internal network. The flaw is an example of improper access control (CWE‑284).

Affected Systems

Affected systems are ONLY the TOTOLINK T6 router running the firmware version 4.1.5cu.748_B20211015 or earlier builds that have not applied the patch. No other vendors are reported in the CNA data. The vulnerability originates within the device's internal CGI interface and does not rely on user interaction beyond sending the HTTP request.

Risk and Exploitability

No CVSS score or EPSS data are currently available, so the quantitative severity is unknown. The vulnerability is remotely exploitable over the local network and can be triggered by any host that can reach the router. Because it allows the disclosure of sensitive device metadata, the risk is moderate to high for individuals or organizations that require strong device anonymity or rely on default firewall settings to block unauthenticated requests. The CVE is not listed in the CISA KEV catalog, but mitigation should still be applied promptly to prevent opportunistic reconnaissance by adversaries.

Generated by OpenCVE AI on August 28, 2026 at 20:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest firmware release that addresses the getDeviceInfo access‑control issue.
  • Configure the router's network settings or use a firewall to restrict access to /cgi-bin/cstecgi.cgi to authenticated users or to a local management subnet only.
  • Regularly review device logs for unexpected POST requests and monitor for anomalous activity.

Generated by OpenCVE AI on August 28, 2026 at 20:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access To Device Information via POST Request on TOTOLINK T6
Weaknesses CWE-284

Fri, 28 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the getDeviceInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain device identification details via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-28T15:40:29.710Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51613

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-28T20:18:04.430

Modified: 2026-08-28T21:20:39.190

Link: CVE-2026-51613

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:45:04Z

Weaknesses