Description
Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized configuration modification via unauthenticated access to the mesh name setting
Action: Patch immediately
AI Analysis

Impact

The setWiFiMeshName function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 fails to enforce authentication, allowing any network client to rename mesh entries by sending a crafted POST request to /cgi-bin/cstecgi.cgi. This unauthorized modification can confuse network management and may serve as an early foothold for further attacks. The weakness is improper access control (CWE-284).

Affected Systems

Any TOTOLINK T6 devices running firmware 4.1.5cu.748_B20211015 are affected. The vulnerability resides in the setWiFiMeshName functionality exposed at /cgi-bin/cstecgi.cgi on the device’s web interface.

Risk and Exploitability

The CVSS score of 9.8 indicates high severity, but the EPSS score of less than 1% shows low likelihood of exploitation. The issue is not listed in CISA KEV, implying no known active exploitation. Nonetheless, any device with the vulnerable firmware can be reached over the local network, and the unauthenticated CGI endpoint allows immediate modification of a mesh name. The attacker must be on or able to reach the local network and send a valid POST request to the specified path. There are no additional prerequisites beyond network access, making the vulnerability highly exploitable in theory.

Generated by OpenCVE AI on September 3, 2026 at 14:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware patch from TOTOLINK that fixes the access control flaw.
  • If a patch is not yet available, restrict access to /cgi-bin/cstecgi.cgi by requiring authentication or firewall the endpoint.
  • As a temporary countermeasure, monitor logs or traffic for unauthorized POST requests to /cgi-bin/cstecgi.cgi and block offending IP addresses.

Generated by OpenCVE AI on September 3, 2026 at 14:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Mesh Entry Renaming on TOTOLINK T6 via Incorrect Access Control

Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Mon, 31 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Mesh Entry Renaming on TOTOLINK T6 via Incorrect Access Control
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-02T18:20:12.232Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51705

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-31T16:18:35.680

Modified: 2026-09-02T19:17:19.820

Link: CVE-2026-51705

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T14:30:05Z

Weaknesses