Executive brief
TOTOLINK T6 is a wireless router that manages network configuration and scheduling for Wi-Fi access points. An unauthenticated attacker can access the router's web interface remotely and retrieve sensitive Wi-Fi scheduling rules without logging in, potentially revealing network configuration details that could be used for further attacks.
Technical details
The vulnerability exists in the getApWiFiSchCfg function within the cstecgi.cgi CGI script, which lacks proper authentication checks. An attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to invoke this function and retrieve AP-specific Wi-Fi scheduling configuration without providing valid credentials. The function is network-accessible and requires no authentication or user interaction. An attacker gains unauthorized access to sensitive configuration information that should be restricted to authenticated administrators. Patch availability for this specific vulnerability is not documented in the advisory.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed