Executive brief
TOTOLINK T6 is a home router that manages Wi-Fi network settings and scheduling. An unauthenticated attacker on the network can retrieve sensitive Wi-Fi scheduling configuration by sending a crafted request, potentially exposing network policies and rules without requiring any credentials.
Technical details
The vulnerability exists in the getWiFiScheduleCfg function within the web-accessible cstecgi.cgi endpoint, which fails to enforce authentication checks. An attacker can send a POST request to /cgi-bin/cstecgi.cgi without credentials to retrieve Wi-Fi scheduling rules and configuration. This is a missing access control vulnerability (CWE-306) affecting an information disclosure function. No authentication is required and the endpoint is network-accessible, allowing any remote user to exploit this. A patch status is not indicated in the advisory.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed