Executive brief
TOTOLINK T6 is a mesh network router used in home and small business networks. The device's web interface contains a missing authentication check in the getMeshRoutingTable function, allowing anyone on the network to retrieve sensitive mesh routing configuration without logging in. An attacker could use this information to map the network topology and identify targets for further attacks.
Technical details
The getMeshRoutingTable function in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 fails to validate user authentication before processing requests. An unauthenticated attacker can send a POST request to the /cgi-bin/cstecgi.cgi endpoint with a crafted payload to extract mesh routing table data. The vulnerability requires network-level access to reach the device's web interface but no prior authentication. This is part of a broader pattern of missing authentication checks across multiple cgi functions in the same firmware version.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed