Executive brief
TOTOLINK T6 is a mesh router used to extend wireless network coverage. An unauthenticated attacker can send a specially crafted web request to alter the mesh pairing configuration, potentially disconnecting authorized devices or allowing unauthorized devices to join the mesh network.
Technical details
The vulnerability is an incorrect access control issue in the setPairCfg function within the cstecgi.cgi web interface of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The function fails to enforce authentication checks before processing mesh pairing configuration changes. An unauthenticated attacker on the network can send a crafted POST request to /cgi-bin/cstecgi.cgi to modify mesh pairing state without providing valid credentials. This allows arbitrary modification of the router's mesh topology and pairing settings. The patch status is not explicitly mentioned in the advisory.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed