Executive brief
TOTOLINK T6 is a mesh Wi-Fi router used to extend wireless network coverage in homes and offices. A vulnerability in the device's firmware allows unauthenticated attackers to remotely trigger mesh slave update coordination by sending a specially crafted request to the device's web interface, potentially disrupting network operations and enabling further compromise.
Technical details
The vulnerability is an authentication bypass and access control deficiency in the informSlaveUpdate function exposed via the cstecgi.cgi CGI script in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The function fails to validate user authentication before processing POST requests to /cgi-bin/cstecgi.cgi, allowing any network-accessible attacker to invoke mesh slave update coordination without credentials. No user interaction or special privileges are required; exploitation requires only network reachability to the device. An attacker can disrupt mesh network synchronization and potentially leverage this for further system compromise. A patch addressing this issue has not been publicly documented as of the advisory date.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed