Description
Incorrect access control in the getRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain remote-management enablement and port information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-28
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the getRemoteCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015, allowing an attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi without authentication and retrieve the status of remote‑management enablement and associated port information. The vulnerability is an improper authorization weakness that leads to the disclosure of configuration details that could aid further attacks, such as lateral movement or exploitation of exposed management interfaces. No execution is possible from the request itself, but the exposed data can be leveraged to plan subsequent attacks.

Affected Systems

All devices running TOTOLINK T6 version 4.1.5cu.748_B20211015 are impacted. The vendor has not supplied a separate patch list, so any installation of the mentioned firmware should be considered vulnerable.

Risk and Exploitability

Because the flaw permits unauthenticated data disclosure, it is of high potential impact for a target that relies on confidentiality of management settings. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, but the absence of a known patch and the ability to obtain sensitive configuration details suggest a notable risk. The vulnerability is not listed in the CISA KEV catalog, yet administrators should not assume it is safe to ignore.

Generated by OpenCVE AI on August 28, 2026 at 21:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable remote‑management functionality in the router’s settings to eliminate the exposed endpoint
  • Upgrade the device firmware to a version that addresses the access‑control flaw, if an update is released
  • Configure network firewall rules to block external or unauthenticated traffic to /cgi-bin/cstecgi.cgi

Generated by OpenCVE AI on August 28, 2026 at 21:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Retrieval of Remote Management Configuration via crafted POST to cstecgi.cgi
First Time appeared Totolink
Totolink t6
Weaknesses CWE-285
Vendors & Products Totolink
Totolink t6

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the getRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain remote-management enablement and port information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-28T18:55:18.234Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51650

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-28T20:18:08.453

Modified: 2026-08-28T21:25:40.287

Link: CVE-2026-51650

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T21:15:03Z

Weaknesses