Description
Incorrect access control in the getWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain advanced wireless settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-28
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the getWiFiAdvancedCfg function of the TOTOLINK T6 router firmware 4.1.5cu.748_B20211015 allows an attacker without authentication to retrieve advanced wireless settings by sending a crafted POST request to /cgi-bin/cstecgi.cgi. The vulnerability is an incorrect access control that exposes sensitive configuration information that could aid in planning further attacks or detailed network reconnaissance.

Affected Systems

The vulnerability affects TOTOLINK Home Router T6 units running firmware version 4.1.5cu.748_B20211015. No other device models or firmware revisions were identified as impacted in the available data.

Risk and Exploitability

The exploitation path requires network access to the router and does not rely on user interaction beyond sending the crafted POST request. Because no EPSS or CVSS score is provided, the exact exploitation probability is uncertain, but the flaw allows unauthenticated information disclosure, which is typically considered high risk. The vulnerability is not listed in the CISA KEV catalog and no public exploit has been documented at this time.

Generated by OpenCVE AI on August 28, 2026 at 21:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to the latest stable release that contains the access control fix.
  • If a firmware update is not yet available, block external access to the /cgi-bin/cstecgi.cgi endpoint using firewall or router configuration rules.
  • Disable remote management features and enforce strong credentials on all administrative interfaces.

Generated by OpenCVE AI on August 28, 2026 at 21:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Advanced Wireless Settings in TOTOLINK T6 Router
Weaknesses CWE-284

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the getWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain advanced wireless settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-28T17:15:28.604Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51632

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-28T20:18:06.503

Modified: 2026-08-28T21:25:22.770

Link: CVE-2026-51632

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T21:30:05Z

Weaknesses