TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.Referenceshttps://github.com/EPhaha/IOT_vuln/blob/main/TOTOLink/T6/README.md