Executive brief
The TOTOLINK T6 router has an access control flaw in its web management interface that allows unauthenticated attackers to retrieve WiFi mesh configuration and runtime state information. An attacker on the network can send a specially crafted request to extract sensitive router configuration details without providing credentials, potentially enabling network mapping or further targeted attacks.
Technical details
The vulnerability is an authentication bypass / missing access control issue in the getWiFiMeshConfig function exposed through the /cgi-bin/cstecgi.cgi endpoint. The function fails to validate that incoming POST requests are from authenticated users, allowing any network-accessible attacker to invoke it and retrieve mesh configuration and runtime state information. This is part of a broader pattern of authentication-absent CGI functions in this firmware version, including similar flaws affecting device info, LAN/WAN configuration, WiFi settings, and system status. No authentication or special user interaction is required; the flaw is directly exploitable via HTTP POST. A patch or firmware update from TOTOLINK is required to remediate this issue.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed