Executive brief
TOTOLINK T6 is a wireless router that manages network connectivity and system configuration. An unauthenticated attacker can exploit missing access control in the setScheduleCfg function to remotely configure forced reboot tasks on the device, causing service disruption and potential operational impact to users and networks relying on the router.
Technical details
The vulnerability is an authentication bypass (missing access control check) in the setScheduleCfg function accessible via POST requests to /cgi-bin/cstecgi.cgi. The vulnerable component fails to validate authentication credentials before processing configuration commands, allowing unauthenticated attackers on the network to trigger administrative actions. An attacker can craft and send a malicious POST request to configure forced reboot tasks without providing valid authentication. The attack requires network-level access to the router's management interface but no prior authentication or credentials. This enables denial-of-service via forced reboots, manipulation of device behavior, and potential persistence of malicious configurations.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed