Description
Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw exists in the function that sets a wireless mesh name on a specific TOTOLINK T6 device. Because the call does not enforce proper authentication, any network‑connected client can send a crafted POST request to the designated CGI endpoint and change the name of a mesh entry. This unauthorized modification can confuse network management, undermine inventories, or serve as a foothold for further exploitation if an attacker can manipulate configuration settings. The weakness is a classic case of improper access control.

Affected Systems

TOTOLINK T6 devices running firmware version 4.1.5cu.748_B20211015 are affected. The vulnerability is tied specifically to the setWiFiMeshName function reachable at /cgi-bin/cstecgi.cgi.

Risk and Exploitability

The absence of an EPSS score leaves the likelihood of exploitation uncertain, but the vulnerability allows unauthenticated modification without additional authentication. KEV does not list this issue, so no current evidence exists that it is actively exploited. However, the unchanged firmware means the attack is trivially reachable on any device still using the vulnerable build. The CVSS score is not provided, but the vectors suggest a high severity for configuration integrity and availability.

Generated by OpenCVE AI on August 31, 2026 at 16:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the device’s firmware version against TOTOLINK’s latest releases and apply the vendor’s patch to rectify the access‑control vulnerability.
  • If an immediate update is not possible, disable the mesh renaming API or enforce authentication on /cgi-bin/cstecgi.cgi by configuring the device’s web interface to require login before any POST requests can be processed.
  • As a temporary countermeasure, monitor network traffic for suspicious POST requests to /cgi-bin/cstecgi.cgi and block IP addresses that attempt to modify mesh names without authentication.

Generated by OpenCVE AI on August 31, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Mesh Entry Renaming on TOTOLINK T6 via Incorrect Access Control
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T15:23:54.328Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51705

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T16:18:35.680

Modified: 2026-08-31T16:18:35.680

Link: CVE-2026-51705

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T16:30:05Z

Weaknesses