CVE-2026-51669
nicheUnauthenticated Configuration Disclosure in TOTOLINK T6 Router (getPairCfg)
CVE-2026-51669 is an incorrect access control flaw (CWE-284) in the getPairCfg function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's management endpoint /cgi-bin/cstecgi.cgi. On success, the attacker obtains the device's pairing and mesh-slave configuration, revealing mesh network settings that could support further attacks; the critical 9.1 CVSS score reflects that the flaw is network-exploitable with no privileges or user interaction required. Owners of TOTOLINK T6 mesh routers on the listed firmware are affected, and no fixed firmware version is identified in the available data. Exploitation status: no public proof-of-concept, no CISA KEV listing, and no known in-the-wild exploitation; EPSS estimates a roughly 0.4% chance of exploitation within 30 days.
What to do: Check TOTOLINK's support/download site for firmware newer than 4.1.5cu.748_B20211015 and upgrade as soon as a patched release is published. Until then, avoid exposing the router's web management interface (cstecgi.cgi) to the WAN — disable WAN-side management or restrict it to trusted source addresses — since exploitation requires no credentials. Defenders should treat leaked mesh pairing/slave configuration as reconnaissance that could enable follow-on attacks against the mesh network.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (version cited in the advisory; other affected versions unconfirmed) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain pairing and mesh-slave configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.