CVE-2026-51664
Summary
| CVE | CVE-2026-51664 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-28 22:16:49 UTC |
| Updated | 2026-08-28 22:16:49 UTC |
| Description | Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Telnet service enablement status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi. |
Risk And Classification
Problem Types: n/a
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.totolink.net/home/menu/detail/menu_listtpl/download/id/190/ids/36.html | [email protected] | www.totolink.net | |
| github.com/ShengWu00/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md | [email protected] | github.com | |
| www.totolink.net | [email protected] | www.totolink.net | |
| github.com/DarkBoulder/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.