Access Control Flaw in TOTOLINK Product Allows Exploitation by Unauthenticated Attackers
CVE-2026-51669
9.1CRITICAL
What is CVE-2026-51669?
An access control vulnerability has been identified in the getPairCfg function of the TOTOLINK T6 version 4.1.5cu.748_B20211015. This flaw allows unauthenticated attackers to issue a specially crafted POST request to the '/cgi-bin/cstecgi.cgi' endpoint, which can lead to unauthorized access to pairing and mesh-slave configuration information. Without proper access controls, this vulnerability enables potential exploitation that jeopardizes device integrity and user privacy.
