Executive brief
TOTOLINK T6 is a residential router that manages network configuration and device scheduling. An unauthenticated attacker on the network can retrieve sensitive scheduling and reboot configuration data by sending a specially crafted request to the router's web interface, potentially enabling unauthorized system control or information disclosure.
Technical details
The vulnerability is an authentication bypass (missing access control) in the getScheduleCfg function of the cstecgi.cgi web interface on TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker with network access can send a POST request to /cgi-bin/cstecgi.cgi to retrieve schedule and scheduled-reboot configuration data. The vulnerability requires network reachability to the device but no prior authentication or credentials. No patch information is currently available.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed