CVE-2026-51721
moderateUnauthenticated access-control flaw in TOTOLINK T6 exposes mesh pairing state
CVE-2026-51721 is an improper access control issue (CWE-284) in the setPairCfg function of the TOTOLINK T6 mesh router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted HTTP POST request to the router's management endpoint /cgi-bin/cstecgi.cgi. Because the function requires no authentication, an attacker with network reachability to the web interface can alter the device's mesh pairing state, which CVSS 3.1 scores as critical (9.1) with high confidentiality and integrity impact. Any TOTOLINK T6 deployment on the cited firmware is affected, particularly units whose management interface is reachable from the WAN or from untrusted LAN clients. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at 0.3%, so no confirmed exploitation is known at this time.
What to do: Check TOTOLINK T6 units for firmware 4.1.5cu.748_B20211015 and watch for a vendor advisory or patched firmware, since no fixed version is specified in the available data. In the meantime, restrict access to the router's management interface (do not expose it to the WAN) and limit which LAN clients can reach /cgi-bin/cstecgi.cgi via firewall or ACL rules. Monitor for crafted POST requests to cstecgi.cgi referencing setPairCfg as a detection indicator.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (firmware version cited in the report; no other ranges specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the mesh pairing state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.