Executive brief
TOTOLINK T6 is a WiFi mesh router used to provide wireless network coverage. An unauthenticated attacker on the network can send a malicious request to alter mesh network configurations, potentially disrupting network operations or gaining control over network settings without authorization.
Technical details
The vulnerability is an incorrect access control (CWE-284) in the setWiFiMeshConfig function of the web administration interface. The vulnerable endpoint /cgi-bin/cstecgi.cgi fails to validate user authentication before processing configuration change requests, allowing any unauthenticated attacker with network access to submit POST requests that alter mesh configurations. No authentication or CSRF token validation is performed. An attacker can exploit this to modify WiFi mesh settings, potentially causing service disruption or compromising network integrity. The vulnerability affects TOTOLINK T6 firmware version 4.1.5cu.748_B20211015.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed