VYPR
advisoryPublished Aug 28, 2026· Updated Aug 29, 2026· 1 source

Totolink T6: 25 Access Control Flaws Disclosed Together Allow Information Leakage

Key findings • 25 incorrect access control vulnerabilities disclosed for Totolink T6 router on August 28, 2026. • All flaws affect firmware version 4.1.5cu.748_B20211015, allowing unauthentic…

Key findings

  • 25 incorrect access control vulnerabilities disclosed for Totolink T6 router on August 28, 2026.
  • All flaws affect firmware version 4.1.5cu.748_B20211015, allowing unauthenticated information disclosure.
  • Vulnerabilities span across network diagnostics, security settings, and system configurations.
  • Exploitation requires sending crafted POST requests to /cgi-bin/cstecgi.cgi.
  • No patches or advisories released by Totolink at the time of disclosure.

On August 28, 2026, a batch of 25 vulnerabilities was disclosed for the Totolink T6 router, all stemming from incorrect access control flaws within the device's web interface. These vulnerabilities, collectively disclosed within a two-hour window, allow unauthenticated attackers to access sensitive diagnostic logs, configuration settings, and operational states. The widespread nature of these flaws across various functionalities highlights a significant oversight in the product's security posture.

The vulnerabilities primarily affect the cgi-bin/cstecgi.cgi endpoint, where various get functions are susceptible to improper access control. This allows attackers to retrieve information that should be protected, including:

  • Network Diagnostics and Status: CVE-2026-51665 (traceroute logs), CVE-2026-51664 (Telnet status), CVE-2026-51648 (WAN information), and CVE-2026-51649 (diagnostic configuration and ping logs).
  • Wireless and Network Configuration: CVE-2026-51663 (wireless scan results), CVE-2026-51651 (Smart QoS rules), CVE-2026-51652 (UPnP status and port mappings), CVE-2026-51650 (remote management settings), and CVE-2026-51641 (WiFi mesh configuration).
  • Security and Access Control Settings: CVE-2026-51660 (IP and port filtering rules), CVE-2026-51659 (URL filter rules), CVE-2026-51658 (DMZ configuration), CVE-2026-51655 (MAC filter rules), CVE-2026-51646 (parental control rules), and CVE-2026-51645 (administrative username retrieval).
  • System and Cloud Services: CVE-2026-51644 and CVE-2026-51647 (cloud remote-control status), CVE-2026-51656 (VPN pass-through and WAN ping filter settings), CVE-2026-51654 (schedule configuration), CVE-2026-51653 (storage feature state), CVE-26-51643 (NTP configuration and time data), and CVE-2026-51642 (mesh routing table).

All disclosed vulnerabilities affect the specific firmware version 4.1.5cu.748_B20211015. The consistent pattern across all 25 CVEs indicates a systemic issue with how the router handles unauthenticated requests to its web interface. While no specific threat actors or exploitation campaigns have been publicly linked to this batch, the ease of exploitation (unauthenticated access via crafted POST requests) makes these flaws a significant risk for any user running the vulnerable firmware.

Totolink has not yet released a statement or patch for these vulnerabilities at the time of this report. Users are advised to monitor the vendor's official channels for any security advisories or firmware updates. Given the number and nature of these flaws, disabling unnecessary services and restricting access to the router's management interface from untrusted networks is a critical mitigation strategy.

This extensive batch of vulnerabilities underscores the importance of regular security audits for IoT devices. The ability for unauthenticated users to glean such a wide array of sensitive information from the Totolink T6 router could pave the way for more targeted attacks or reconnaissance efforts by malicious actors. Users of the T6 router should be vigilant for any security updates from Totolink and consider the potential risks associated with running outdated firmware.

The affected firmware version is 4.1.5cu.748_B20211015.

CVEs included in this batch are: CVE-2026-51665, CVE-2026-51664, CVE-2026-51663, CVE-2026-51662, CVE-2026-51661, CVE-2026-51660, CVE-2026-51659, CVE-2026-51658, CVE-2026-51657, CVE-2026-51656, CVE-2026-51655, CVE-2026-51654, CVE-2026-51653, CVE-2026-51652, CVE-2026-51651, CVE-2026-51650, CVE-2026-51649, CVE-2026-51648, CVE-2026-51647, CVE-2026-51646, CVE-2026-51645, CVE-2026-51644, CVE-2026-51643, CVE-2026-51642, CVE-2026-51641.

Synthesized by Vypr AI