Executive brief
The TOTOLINK T6 mesh router allows attackers without credentials to delete managed slave devices in the network by sending a crafted request. An attacker could disrupt network operations by removing devices, preventing users from extending their Wi-Fi coverage and forcing network reconfiguration.
Technical details
The delDevice function in the cstecgi.cgi CGI script lacks proper authentication checks, allowing unauthenticated POST requests to delete managed slave devices from the mesh network. An attacker on the network or with access to the router's web interface can exploit this by sending a crafted POST request to /cgi-bin/cstecgi.cgi without providing valid credentials. This results in unauthorized removal of slave devices from the mesh topology, disrupting network connectivity and availability. No patch information is currently available.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed
- other: Reported as CVE-2026-51729