Executive brief
TOTOLINK T6 is a mesh WiFi router used to extend wireless coverage across homes and offices. An authentication bypass vulnerability in the device's web interface allows unauthenticated attackers to retrieve sensitive pairing and mesh network configuration information, potentially enabling unauthorized network access or device compromise.
Technical details
The getPairCfg function in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 lacks proper authentication checks, allowing unauthenticated access to pairing and mesh-slave configuration data. An attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to retrieve this sensitive configuration information over the network without requiring valid credentials. The vulnerability exposes mesh pairing credentials and network topology details that could facilitate unauthorized device enrollment or network manipulation. No patch information is currently available.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed