Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-51645: TOTOLINK T6 router reveals admin username to anyone
CVE-2026-51645 · published 6 days ago
Summary
The router’s web interface lets anyone send a specially crafted request and see the administrator’s login name. This makes it easier for attackers to plan further attacks against your network. Apply the latest firmware update from the vendor and limit access to the router’s management pages to trusted users only.
Original advisory text
Incorrect access control in the getPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the administrative username via sending a crafted POST reques...
Incorrect access control in the getPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the administrative username via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published28 Aug 2026
Updated2 Sep 2026
First seen28 Aug 2026
Monitor software like this
Free during beta