Executive brief
TOTOLINK T6 is a wireless mesh router. An unauthenticated attacker can send a crafted web request to obtain sensitive information about nearby mesh network devices, exposing the network topology and device identities without requiring a password or login.
Technical details
The vulnerability is an authentication bypass (missing access control) in the getMeshNeighborTable function within the web interface of TOTOLINK T6. The vulnerable endpoint (/cgi-bin/cstecgi.cgi) does not properly validate user authentication before processing requests to retrieve mesh neighbor table information. An unauthenticated attacker on the network can craft a POST request to this endpoint to retrieve sensitive mesh network topology details. The attack requires network reachability to the router's web interface but no authentication credentials or user interaction. This allows information disclosure about mesh network structure and connected devices.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed