CVE-2026-51721

TOTOLINK · T6

An improper access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to modify mesh pairing configurations via a crafted POST request to the cstecgi.cgi endpoint.

Executive summary

A critical access control vulnerability in TOTOLINK T6 routers allows unauthenticated remote attackers to manipulate mesh network settings, posing a significant risk to network integrity.

Vulnerability

This vulnerability involves an incorrect access control implementation within the setPairCfg function. It allows any unauthenticated attacker to send a malicious POST request to the cgi-bin/cstecgi.cgi endpoint to alter the device's mesh pairing state.

Business impact

The ability for an unauthenticated attacker to modify mesh pairing configurations can lead to unauthorized access to the network, interception of traffic, or complete loss of network control. Given the CVSS score of 9.1, this vulnerability is classified as critical, as it bypasses authentication mechanisms and enables remote configuration changes that could facilitate further exploitation of the internal environment.

Remediation

Immediate Action: Contact the vendor or consult the official TOTOLINK support portal to determine if a firmware update is available for the T6 model to patch this specific access control flaw.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at /cgi-bin/cstecgi.cgi and inspect device logs for unauthorized changes to mesh configuration settings.

Compensating Controls: Restrict management interface access to trusted internal IP addresses and employ a firewall to block external access to the web-based administrative endpoints of the device.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical nature of this vulnerability and the lack of authentication required to trigger the flaw, immediate action is required to secure affected devices. Administrators should verify the current firmware version and apply the latest vendor-supplied patches as soon as they are released to prevent unauthorized configuration changes.

More TOTOLINK CVEs

Sources