Executive brief
TOTOLINK T6 is a wireless router used to provide network connectivity in homes and small offices. An unauthenticated attacker can remotely modify the device's time synchronization settings via a web request, potentially disrupting network operations, breaking certificate validation, and interfering with time-dependent services and logging.
Technical details
The vulnerability is an authentication bypass in the setNtpCfg function of the cstecgi.cgi web interface on TOTOLINK T6 4.1.5cu.748_B20211015. An attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to modify NTP (Network Time Protocol) configuration without providing valid credentials. The vulnerability requires network access to the router's web management interface (typically port 80/443) but no user interaction or prior authentication. An attacker can alter time settings, which could impact certificate validation, system logs, and time-dependent features. Patches or firmware updates may be available from TOTOLINK.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed