Executive brief
TOTOLINK T6 is a wireless router used to provide internet connectivity in homes and small offices. The device's reboot function lacks proper access controls, allowing attackers on the network to force an immediate device restart without any authentication, disrupting connectivity and operations.
Technical details
An access control vulnerability exists in the RebootSystem function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The vulnerability is triggered via a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. An unauthenticated attacker with network reachability to the device can trigger an arbitrary immediate reboot without authentication credentials. This results in denial of service and network unavailability. The attack requires only network access and no user interaction.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed