External risk intelligence

TOTOLINK T6 Mesh Rename Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51705

The vulnerability exists in a home networking device (TOTOLINK T6) that manages wireless mesh configurations. These devices are designed to act as gateways or access points and are frequently exposed to the network, with administrative interfaces often reachable over the local network or, in misconfigured deployments, potentially exposed to the internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security flaw has been identified in specific TOTOLINK home networking devices, allowing unauthenticated attackers to potentially rename mesh network entries. This could enable unauthorized control or disruption of network configurations. The main concern is confirming relevance and exposure within your environment.

  • Unauthenticated network renaming flaw.
  • Impacts home networking devices.
  • Verify relevance and exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can rename mesh entries on a TOTOLINK T6 router by sending a specially crafted POST request to the device's web interface. This bypasses access controls within the setWiFiMeshName function, allowing the attacker to potentially disrupt network configurations.

  • Requires network access.
  • Triggers via crafted POST request.
  • Risks configuration disruption.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to rename mesh entries on a TOTOLINK T6 router. This occurs when the router is accessible and the attacker can send a specially crafted POST request to a specific CGI endpoint.

  • Affected asset: Router mesh configuration.
  • Exposure: Unauthenticated network request.
  • Consequence: Unwanted configuration changes.

Operational Fix

Recommended remediation, mitigation, and detection steps

The discovery of an unauthenticated remote code execution vulnerability in TOTOLINK T6 mesh devices necessitates immediate attention from teams responsible for network infrastructure and device management. The first practical step involves identifying all deployed TOTOLINK T6 devices, assessing their network exposure and business criticality, and then confirming the accountable owner for remediation. Planning for patching or other risk mitigation strategies should follow this initial assessment.

  • Network or Infrastructure teams should own the issue.
  • Verify device reachability and criticality.
  • Plan remediation based on exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TOTOLINK T6 device?

The TOTOLINK T6 is a home networking device designed to function as a wireless router or access point. It creates mesh networks, which allow multiple units to work together to extend Wi-Fi coverage across a home or small office. This device acts as a central hub, managing how wireless clients connect and communicate within the local network infrastructure.

What does CWE-284 mean for CVE-2026-51705?

CWE-284 refers to Improper Access Control. In the context of this vulnerability, it means the device fails to verify if a user has permission before performing a sensitive action. Specifically, the software lacks a requirement for authentication before allowing a change to mesh network settings, letting anyone who can reach the device’s administrative interface modify its configuration.

How does an attacker trigger this vulnerability?

An attacker triggers the bug by sending a specifically formatted POST request to the device's /cgi-bin/cstecgi.cgi endpoint. This action calls the setWiFiMeshName function without needing a login. Simply navigating to the router's web interface or viewing the network status does not trigger the vulnerability; it requires a deliberate, malicious request designed to alter the mesh configuration.

Is my TOTOLINK T6 at risk?

According to Halo Surface Signal, this vulnerability is particularly relevant if your TOTOLINK T6 is reachable over the network. While these devices are primarily for home use, they are often accessible via local networks. If a device is misconfigured or lacks proper firewalling, the administrative interface might be exposed to the wider internet, significantly increasing the likelihood of unauthorized access attempts.

Do I need to take action if I use this router?

Yes, you should begin by creating an inventory of all TOTOLINK T6 devices in your environment to understand where they are deployed. Determine if these units are accessible from untrusted networks and evaluate their impact on your operations. Once you have identified the affected devices and their network placement, prioritize them for patching or implement network-level controls to restrict access to their management interfaces.

References