Access Control Flaw in TOTOLINK Router Software Exposes Sensitive Firmware Information
CVE-2026-51671
7.5HIGH
What is CVE-2026-51671?
An access control vulnerability in the getCloudDownloadStatus function of the TOTOLINK T6 allows unauthorized users to exploit this flaw. This vulnerability enables attackers to send specially crafted POST requests to the /cgi-bin/cstecgi.cgi endpoint. By doing so, they can obtain sensitive information about the cloud firmware download status, posing significant risks to device integrity and user security.
