Junglewise Threat Intelligence

CVE-2026-51640: TOTOLINK T6 auth bypass in getMeshNeighborTable

CVE-2026-51640 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a wireless mesh router. An unauthenticated attacker can send a crafted web request to obtain sensitive information about nearby mesh network devices, exposing the network topology and device identities without requiring a password or login.

Technical details

The vulnerability is an authentication bypass (missing access control) in the getMeshNeighborTable function within the web interface of TOTOLINK T6. The vulnerable endpoint (/cgi-bin/cstecgi.cgi) does not properly validate user authentication before processing requests to retrieve mesh neighbor table information. An unauthenticated attacker on the network can craft a POST request to this endpoint to retrieve sensitive mesh network topology details. The attack requires network reachability to the router's web interface but no authentication credentials or user interaction. This allows information disclosure about mesh network structure and connected devices.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References