Junglewise Threat Intelligence

CVE-2026-51669: TOTOLINK T6 authentication bypass in getPairCfg

CVE-2026-51669 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a mesh WiFi router used to extend wireless coverage across homes and offices. An authentication bypass vulnerability in the device's web interface allows unauthenticated attackers to retrieve sensitive pairing and mesh network configuration information, potentially enabling unauthorized network access or device compromise.

Technical details

The getPairCfg function in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 lacks proper authentication checks, allowing unauthenticated access to pairing and mesh-slave configuration data. An attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to retrieve this sensitive configuration information over the network without requiring valid credentials. The vulnerability exposes mesh pairing credentials and network topology details that could facilitate unauthorized device enrollment or network manipulation. No patch information is currently available.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References