ZeroHour

CVE-2026-51721

moderate

Unauthenticated access-control flaw in TOTOLINK T6 exposes mesh pairing state

CVSS 3.1
9.1 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-51721 is an improper access control issue (CWE-284) in the setPairCfg function of the TOTOLINK T6 mesh router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted HTTP POST request to the router's management endpoint /cgi-bin/cstecgi.cgi. Because the function requires no authentication, an attacker with network reachability to the web interface can alter the device's mesh pairing state, which CVSS 3.1 scores as critical (9.1) with high confidentiality and integrity impact. Any TOTOLINK T6 deployment on the cited firmware is affected, particularly units whose management interface is reachable from the WAN or from untrusted LAN clients. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at 0.3%, so no confirmed exploitation is known at this time.

What to do: Check TOTOLINK T6 units for firmware 4.1.5cu.748_B20211015 and watch for a vendor advisory or patched firmware, since no fixed version is specified in the available data. In the meantime, restrict access to the router's management interface (do not expose it to the WAN) and limit which LAN clients can reach /cgi-bin/cstecgi.cgi via firewall or ACL rules. Monitor for crafted POST requests to cstecgi.cgi referencing setPairCfg as a detection indicator.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (firmware version cited in the report; no other ranges specified)
Estimated exposure
moderatelikely a few thousand to low tens of thousands of internet-exposed units (estimated; exact install base unknown) — No published install counts exist for the T6 model specifically, but TOTOLINK consumer routers routinely appear in internet-wide scans in the tens of thousands, and this single 2021-era mesh model plausibly accounts for a subset in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the mesh pairing state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.