In TOTOLINK T6 V4.1.5cu.709B20210518, there is a hard coded password for root in /etc/shadow.sample.
In TOTOLINK T6 V4.1.5cu.709B20210518, there is an execute arbitrary command in cstecgi.cgi.
TOTOLINK T6 V4.1.5cu.709B20210518 is vulnerable to Buffer Overflow via cstecgi.cgi
TOTOLINK T6 V4.1.5cu.709B20210518 is vulnerable to command injection via cstecgi.cgi