Executive brief
TOTOLINK T6 is a wireless router used in homes and small offices. An unauthenticated attacker can send a crafted web request to alter the device's logging configuration, potentially disabling audit trails or redirecting logs to attacker-controlled servers. This could allow an attacker to hide their tracks while conducting further attacks on the device or connected network.
Technical details
The setSyslogCfg function in the cstecgi.cgi web interface lacks proper authentication checks, resulting in an access control vulnerability. An attacker can send an unauthenticated POST request to /cgi-bin/cstecgi.cgi with crafted parameters to modify syslog configuration settings. No authentication or session token is required to invoke this function, making it accessible over the network to any attacker. Successful exploitation allows an attacker to alter logging behavior, potentially disabling forensic capabilities or redirecting logs off-device. Patch availability depends on TOTOLINK's response to the vulnerability disclosure.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed