ZeroHour

CVE-2026-51642

niche

Unauthenticated Information Disclosure in TOTOLINK T6 Mesh Router

CVSS 3.1
7.5 high
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51642 is an improper access control flaw (CWE-284) in the getMeshRoutingTable function of the TOTOLINK T6 web management interface, firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi, requiring no credentials or user interaction. Successful exploitation discloses mesh routing information, a confidentiality-only impact with no evidence of code execution or device compromise in the available data. Any T6 unit running the affected firmware is exposed, particularly where the web interface is reachable from untrusted networks. No public proof-of-concept exists, the flaw is not in CISA KEV, and its EPSS of 0.4% indicates exploitation risk over the next 30 days is currently low.

What to do: Inventory any TOTOLINK T6 devices and verify their firmware version against 4.1.5cu.748_B20211015; no fixed version is specified in the available data, so monitor TOTOLINK advisories for a patched release. As an interim mitigation, ensure the T6 web interface (cstecgi.cgi) is not reachable from the WAN or untrusted networks by disabling remote management and restricting access at the firewall. Given the impact is limited to disclosure of mesh routing information, prioritize remediation mainly for internet-exposed units.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (the only version identified in the disclosure; other firmware builds are not specified)
Estimated exposure
nichelikely thousands of units at most, with only a subset internet-exposed; no public install or scan counts available for this model — No vendor shipment figures or internet-scan counts exist for the T6; the estimate reflects that it is a single consumer mesh model from a budget brand, typically deployed behind NAT so only a minority of units expose the management…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getMeshRoutingTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh routing information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.