Executive brief
TOTOLINK T6 is a wireless router used to provide network connectivity in homes and small offices. An unauthenticated attacker on the network can send a specially crafted request to reconfigure or disable the router's wireless networks without any credentials, disrupting network availability and potentially forcing legitimate users offline.
Technical details
The setWiFiEasyCfg function in the TOTOLINK T6 router lacks proper authentication checks before processing wireless configuration changes. An attacker can send an unauthenticated POST request to the CGI endpoint /cgi-bin/cstecgi.cgi to invoke this function and modify or disable wireless network settings. No credentials or session tokens are required—the vulnerability is a classic broken access control flaw that allows any network-adjacent attacker to reconfigure the device's WiFi parameters directly. The device firmware version 4.1.5cu.748_B20211015 is confirmed vulnerable. Patch availability has not been confirmed in the advisory.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed