Executive brief
The TOTOLINK T6 router is a wireless networking device used to provide internet connectivity and network services to homes and offices. An unauthenticated attacker can send a specially crafted web request to remotely change the administrator account credentials, gaining complete control over the device and enabling them to modify network settings, intercept traffic, or lock out legitimate users.
Technical details
This vulnerability is an authentication bypass and privilege escalation flaw in the setPasswordCfg function exposed via the /cgi-bin/cstecgi.cgi endpoint on TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The vulnerable function fails to validate user authentication before allowing administrative password changes, allowing an unauthenticated attacker to send a POST request to change the admin account password. No authentication credentials or special preconditions are required—the vulnerability is accessible over the network to anyone with network access to the device. Successful exploitation results in complete device compromise and loss of administrative control for the legitimate owner.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed