CVE-2026-51641: TOTOLINK T6 vulnerability
Incorrect access control in the getWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to obtain mesh configuration and runtime state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TOTOLINK T6to a version that resolves this vulnerability.Fixed in 4.1.5cu.748_B20211015 - Compensating control
Restrict access to /cgi-bin/cstecgi.cgi (e.g., via network ACL/WAF/firewall) to authenticated/admin users only to prevent unauthenticated retrieval of mesh configuration and runtime state information through crafted POST requests.
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker who can send a crafted POST request to the device's /cgi-bin/cstecgi.cgi endpoint can exploit it. The affected function exposes mesh configuration and runtime-state information.
Which product and firmware version are identified as affected?
The reported affected product is the TOTOLINK T6 running firmware version 4.1.5cu.748_B20211015.