Executive brief
TOTOLINK T6 is a WiFi router used by home and small business users to provide network connectivity. An unauthenticated attacker on the network can modify the device's LED behavior settings by sending a specially crafted request, allowing them to control physical indicators without authorization. This is one of many missing authentication flaws affecting the router's web interface, potentially enabling attackers to reconfigure the device remotely.
Technical details
The setLedCfg function in the cstecgi.cgi CGI script fails to implement proper access control, allowing unauthenticated POST requests to modify LED configuration settings. The vulnerability can be exploited by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. While modifying LED behavior alone has limited impact, this flaw is part of a broader pattern of missing authentication checks across multiple device functions, enabling attackers to reconfigure network settings, reboot the device, and extract sensitive information without credentials. No patch information is publicly available at this time.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed