CVE-2026-51642
nicheUnauthenticated Information Disclosure in TOTOLINK T6 Mesh Router
CVE-2026-51642 is an improper access control flaw (CWE-284) in the getMeshRoutingTable function of the TOTOLINK T6 web management interface, firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi, requiring no credentials or user interaction. Successful exploitation discloses mesh routing information, a confidentiality-only impact with no evidence of code execution or device compromise in the available data. Any T6 unit running the affected firmware is exposed, particularly where the web interface is reachable from untrusted networks. No public proof-of-concept exists, the flaw is not in CISA KEV, and its EPSS of 0.4% indicates exploitation risk over the next 30 days is currently low.
What to do: Inventory any TOTOLINK T6 devices and verify their firmware version against 4.1.5cu.748_B20211015; no fixed version is specified in the available data, so monitor TOTOLINK advisories for a patched release. As an interim mitigation, ensure the T6 web interface (cstecgi.cgi) is not reachable from the WAN or untrusted networks by disabling remote management and restricting access at the firewall. Given the impact is limited to disclosure of mesh routing information, prioritize remediation mainly for internet-exposed units.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (the only version identified in the disclosure; other firmware builds are not specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getMeshRoutingTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh routing information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.