Description
Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Telnet service enablement status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-28
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in an improper access control within the getTelnetCfg function, enabling unauthenticated attackers to query whether Telnet is enabled by sending a crafted POST request to /cgi-bin/cstecgi.cgi. The disclosed data is purely the Telnet enablement status, which provides an attacker insight into the router's configuration and potential attack surface, aiding reconnaissance and future exploitation planning.

Affected Systems

TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 are affected by this weakness. No other vendors or versions are listed in the available data.

Risk and Exploitability

A formal CVSS score is not provided, and the EPSS score is unavailable, so the quantitative severity cannot be determined. The vulnerability can be exploited over an unauthenticated network connection by sending a simple crafted POST request, and the KEV catalog does not list it as currently exploited. Because the attack requires no credentials and only exposes service status, the immediate risk is moderate; however, if Telnet is enabled, the disclosed information can facilitate further attacks. The availability of an unauthenticated access point remains a noteworthy weakness.

Generated by OpenCVE AI on August 29, 2026 at 00:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the vendor supplied firmware update that corrects the access control in getTelnetCfg.
  • Disable the Telnet service or block port 23 on the router to eliminate the exposed service.
  • Configure firewall or ACL rules to reject unauthenticated POST requests to /cgi-bin/cstecgi.cgi.

Generated by OpenCVE AI on August 29, 2026 at 00:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Telnet Enablement Status in TOTOLINK T6 Firmware
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Telnet service enablement status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-28T19:41:44.019Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51664

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T22:16:49.637

Modified: 2026-08-28T22:16:49.637

Link: CVE-2026-51664

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:30:17Z

Weaknesses