Description
Incorrect access control in the getWanInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN information returned by the endpoint via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-28
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015 have a weak access control mechanism in the getWanInfo function. This flaw allows an attacker who has not authenticated to obtain the device’s WAN information by sending a specially crafted POST request to /cgi-bin/cstecgi.cgi. The disclosed data may reveal public IP addresses, gateway details, and DNS settings that can facilitate further reconnaissance or targeted attacks against the network.

Affected Systems

The exposure applies to the TOTOLINK T6 router family, specifically firmware version 4.1.5cu.748_B20211015. No other firmware or hardware versions are noted in the advisory.

Risk and Exploitability

The vulnerability permits unauthenticated data extraction from the device; the likely attack vector is remote via the web interface, though specific network prerequisites are not detailed in the description. EPSS is currently not reported, and the attack is not listed in the CISA KEV catalog, but the lack of authentication still represents a significant information disclosure risk. Due to the absence of a CVSS score, the severity assessment must rely on the factual impact: any attacker able to reach the device can gain WAN configuration details.

Generated by OpenCVE AI on August 28, 2026 at 21:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest TOTOLINK T6 firmware that addresses the access control issue
  • Restrict web interface access to trusted IP addresses only
  • Block the /cgi-bin/cstecgi.cgi endpoint or disable the getWanInfo function via firewall rules

Generated by OpenCVE AI on August 28, 2026 at 21:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Fri, 28 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to WAN Information via Weak Access Control in TOTOLINK T6
Weaknesses CWE-200
CWE-284

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the getWanInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN information returned by the endpoint via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-28T17:57:35.820Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51648

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-28T20:18:08.240

Modified: 2026-08-28T21:25:40.287

Link: CVE-2026-51648

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T21:30:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control