Junglewise Threat Intelligence

CVE-2026-51721: TOTOLINK T6 access control bypass in setPairCfg

CVE-2026-51721 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a mesh router used to extend wireless network coverage. An unauthenticated attacker can send a specially crafted web request to alter the mesh pairing configuration, potentially disconnecting authorized devices or allowing unauthorized devices to join the mesh network.

Technical details

The vulnerability is an incorrect access control issue in the setPairCfg function within the cstecgi.cgi web interface of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The function fails to enforce authentication checks before processing mesh pairing configuration changes. An unauthenticated attacker on the network can send a crafted POST request to /cgi-bin/cstecgi.cgi to modify mesh pairing state without providing valid credentials. This allows arbitrary modification of the router's mesh topology and pairing settings. The patch status is not explicitly mentioned in the advisory.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References