Junglewise Threat Intelligence

CVE-2026-51705: TOTOLINK T6 auth bypass in setWiFiMeshName

CVE-2026-51705 · Severity: critical · CVSS 9.8 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a mesh WiFi router used to extend wireless coverage throughout homes and offices. This vulnerability allows unauthenticated attackers to rename mesh network entries by sending a specially crafted request to the device's web interface, potentially causing network confusion and disrupting connectivity management capabilities.

Technical details

The setWiFiMeshName function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 lacks proper authentication controls. An attacker can send an unauthenticated POST request to /cgi-bin/cstecgi.cgi to rename mesh entries without requiring login credentials. The vulnerability is accessible over the network to any unauthenticated user who can reach the device's web interface. This allows an attacker to disrupt mesh network configuration and potentially cause operational issues. The underlying issue is an access control bypass in the CGI handler, where the setWiFiMeshName function fails to validate user credentials before executing privileged operations.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References