Executive brief
TOTOLINK T6 is a wireless router used in home and small office networks. An unauthenticated attacker can remotely reconfigure critical settings including WAN connection, Wi-Fi parameters, and device initialization without any login credentials, potentially disrupting network connectivity or changing security configurations.
Technical details
The vulnerability is an authentication bypass in the setWizardCfg function of the cstecgi.cgi web interface in TOTOLINK T6firmware 4.1.5cu.748_B20211015. An attacker can send a crafted HTTP POST request to /cgi-bin/cstecgi.cgi without authentication to modify WAN, Wi-Fi, and device initialization settings. The vulnerability requires only network reachability to the router's web interface (default port 80) and no user interaction. An attacker can modify network configurations, change Wi-Fi SSID/password, or reset initialization state, effectively compromising device functionality and security. No patch status is currently known from the advisory.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed