CVE-2026-51642

TOTOLINK · T6

An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to retrieve sensitive mesh routing information via a crafted POST request.

Executive summary

A critical access control flaw in the TOTOLINK T6 router allows unauthenticated remote attackers to exfiltrate sensitive network topology data.

Vulnerability

The vulnerability resides in the getMeshRoutingTable function, which fails to perform necessary authentication checks. An unauthenticated attacker can exploit this by sending a specifically crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to bypass security controls and access internal mesh routing tables.

Business impact

The exposure of mesh routing information provides attackers with a map of the internal network architecture, significantly lowering the barrier for lateral movement and further exploitation. With a CVSS score of 7.5, this vulnerability represents a high risk to the confidentiality of network configuration data, potentially facilitating follow on attacks against connected devices and infrastructure.

Remediation

Immediate Action: Review the official TOTOLINK support portal for firmware updates addressing this specific vulnerability and apply them immediately if available.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at /cgi-bin/cstecgi.cgi, particularly from external or untrusted sources.

Compensating Controls: Implement strict firewall rules to prevent unauthorized external access to the administrative and CGI interfaces of the router, effectively segmenting the device from the public internet.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the exposure of internal routing data, organizations utilizing the TOTOLINK T6 should prioritize restricting access to the device management interface. Administrators must verify if a vendor patch is available and apply it as soon as possible to mitigate the risk of network reconnaissance by unauthorized actors.

More TOTOLINK CVEs

Sources