Description
Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-28
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an unauthenticated attacker to retrieve Wi‑Fi Access Control List (ACL) rules from a TOTOLINK T6 device. The flaw resides in the getWiFiAclRules function, which incorrectly permits any user with network access to send a crafted POST request to /cgi-bin/cstecgi.cgi and receive the ACL contents. The primary impact is the compromise of confidentiality for the network configuration, potentially revealing which devices are whitelisted or blocked. The weakness is characteristic of an access control failure, enabling data disclosure without authentication. The CVE description specifies that no credentials are required for exploitation; the attacker only needs the ability to reach the device's HTTP endpoint.

Affected Systems

Affected devices are TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No other vendors or product lines are mentioned. Users of this specific firmware revision should verify their device model and version against the description to determine exposure.

Risk and Exploitability

Because the flaw is remote and requires no prior authentication, an attacker can exploit it from any location that can reach the router's web interface. The CVSS score is not provided, and the EPSS score is absent, so the quantitative exploitation likelihood is unknown. The vulnerability is not listed in CISA KEV, suggesting no known in‑field exploitation yet. Nevertheless, the attacker can obtain sensitive network configuration details, which may be leveraged in a broader attack strategy. Given the unrestricted access and lack of mitigations by default, the vulnerability is considered high risk for any exposed device.

Generated by OpenCVE AI on August 28, 2026 at 20:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to the latest version that removes the improper access control flaw.
  • Apply network segmentation or firewall rules to restrict external access to the /cgi-bin/cstecgi.cgi endpoint, limiting exposure to trusted internal networks.
  • Ensure that local network security best practices are followed, such as disabling remote management, changing default credentials, and disabling unused services to reduce the attack surface.

Generated by OpenCVE AI on August 28, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Fri, 28 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Wi‑Fi ACL Rules via getWiFiAclRules Function
Weaknesses CWE-284

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-28T17:19:15.993Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51636

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-28T20:18:06.933

Modified: 2026-08-28T21:25:22.770

Link: CVE-2026-51636

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T21:30:05Z

Weaknesses