CVE-2026-51641
moderateUnauthenticated mesh-config disclosure in TOTOLINK T6 router
CVE-2026-51641 is an incorrect access control flaw (CWE-284) in the getWiFiMeshConfig function of TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and the device returns mesh configuration and runtime state information without any credential check. Impact is confidentiality-only (CVSS 7.5, C:H/I:N/A:N): the attacker gains WiFi mesh settings and live device state useful for reconnaissance or follow-on attacks, with no integrity or availability impact. Only TOTOLINK T6 units running the affected firmware build are affected, and remote exploitation requires the router's web management interface to be reachable from an untrusted network such as the internet. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates a roughly 0.4% probability of exploitation within 30 days (30th percentile).
What to do: Inventory TOTOLINK T6 units and check for firmware 4.1.5cu.748_B20211015; no fixed release is confirmed in the available data, so check TOTOLINK support for an updated build rather than assuming any specific version is safe. Until patched, do not expose the router's web management interface (/cgi-bin/cstecgi.cgi) to untrusted networks — disable remote/WAN administration or restrict it to a trusted management network, since exploitation requires no credentials or user interaction. Monitor for unauthenticated POST requests to /cgi-bin/cstecgi.cgi referencing getWiFiMeshConfig as an indicator of probing, though no public PoC or in-the-wild exploitation is currently known.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (only build confirmed affected in available data; other firmware versions not confirmed) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh configuration and runtime state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.