ZeroHour

CVE-2026-51641

moderate

Unauthenticated mesh-config disclosure in TOTOLINK T6 router

CVSS 3.1
7.5 high
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51641 is an incorrect access control flaw (CWE-284) in the getWiFiMeshConfig function of TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and the device returns mesh configuration and runtime state information without any credential check. Impact is confidentiality-only (CVSS 7.5, C:H/I:N/A:N): the attacker gains WiFi mesh settings and live device state useful for reconnaissance or follow-on attacks, with no integrity or availability impact. Only TOTOLINK T6 units running the affected firmware build are affected, and remote exploitation requires the router's web management interface to be reachable from an untrusted network such as the internet. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates a roughly 0.4% probability of exploitation within 30 days (30th percentile).

What to do: Inventory TOTOLINK T6 units and check for firmware 4.1.5cu.748_B20211015; no fixed release is confirmed in the available data, so check TOTOLINK support for an updated build rather than assuming any specific version is safe. Until patched, do not expose the router's web management interface (/cgi-bin/cstecgi.cgi) to untrusted networks — disable remote/WAN administration or restrict it to a trusted management network, since exploitation requires no credentials or user interaction. Monitor for unauthenticated POST requests to /cgi-bin/cstecgi.cgi referencing getWiFiMeshConfig as an indicator of probing, though no public PoC or in-the-wild exploitation is currently known.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (only build confirmed affected in available data; other firmware versions not confirmed)
Estimated exposure
moderatelow thousands to low tens of thousands of devices worldwide (single model, single confirmed firmware build); no install-base data available — Deployment-pattern estimate: TOTOLINK is a budget consumer-router brand whose overall internet-exposed footprint in public scans has historically been in the tens of thousands across all models, so one model pinned to a single 2021…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh configuration and runtime state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.