Sceawere

Vulnerability Detail

CVE-2026-51669UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TOTOLINK T6 Improper Access Control

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
1d ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain pairing and mesh-slave configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-31T14:17:14.353Z",
  "pubdate": "2026-08-31T14:17:14.353Z",
  "executiveSummary": "The TOTOLINK T6, specifically version 4.1.5cu.748_B20211015, contains an improper access control vulnerability within the getPairCfg function.\nThis security flaw allows unauthenticated remote attackers to bypass authentication mechanisms and retrieve sensitive configuration data, including pairing information and mesh-slave settings.\nThe vulnerability resides within the processing logic of the /cgi-bin/cstecgi.cgi interface.\nSuccessful exploitation results in the unauthorized disclosure of device configuration, which may facilitate further network compromise, lateral movement, or unauthorized device management.\nThe risk is categorized as high due to the lack of required authentication for an operation that exposes critical system parameters.\nAttackers do not require prior access or valid credentials, as the vulnerability can be triggered via a crafted POST request sent directly to the CGI interface.",
  "technicalDetails": "The vulnerability is localized in the getPairCfg function, which is exposed through the /cgi-bin/cstecgi.cgi binary component. The root cause is a failure to implement or validate authentication tokens for requests targeting this specific function within the CGI handler.\nThe /cgi-bin/cstecgi.cgi interface acts as the primary gateway for administrative actions and status retrieval. The application logic fails to perform a session verification check when a POST request containing specific parameters invokes getPairCfg. Consequently, the function proceeds to execute its intended routine—retrieving and returning internal configuration metadata—without confirming the caller's authorization level.\nThe attack flow involves an adversary crafting a specialized HTTP POST request directed at the /cgi-bin/cstecgi.cgi URI. By manipulating the request body to target the getPairCfg function, the attacker bypasses the expected security gate. The backend routine processes the input and responds with a data structure (typically JSON or XML) containing sensitive information, such as mesh-slave credentials, pairing tokens, and network topology details.\nBecause the function does not restrict access to authenticated session identifiers, the internal state of the mesh network is exposed to any actor with network visibility to the device's management interface. This includes local area network (LAN) access or potentially the wide area network (WAN) if the web management interface is exposed to the internet.\nThe impact of this vulnerability is significant, as the exfiltrated configuration data can be leveraged to gain deep insight into the mesh infrastructure. By obtaining mesh-slave configurations, an attacker may be able to masquerade as legitimate nodes, intercept traffic, or manipulate the device settings further. This effectively transitions the device from a secure network appliance to an information leak point, providing the necessary reconnaissance for subsequent exploitation steps or total device takeover."
}
CVE-2026-51669: TOTOLINK T6 Improper Access Control (CRITICAL Severity, CVSS: 9.1) - Sceawere