Junglewise Threat Intelligence

CVE-2026-51637: TOTOLINK T6 incorrect access control in getMeshPortalTable

CVE-2026-51637 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a mesh WiFi router that manages network connections and device configurations. An authentication bypass flaw in its web interface allows unauthenticated attackers to retrieve sensitive mesh portal table information, potentially exposing network topology and connected device details without any credentials.

Technical details

The vulnerability is an incorrect access control issue in the getMeshPortalTable function within the cstecgi.cgi web interface of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to bypass authentication and retrieve mesh portal table information, which may include network configuration and device connectivity details. No user interaction or special privileges are required. The vulnerability is network-accessible and affects a function that should be protected by authentication controls.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References