Executive brief
TOTOLINK T6 is a wireless router used in homes and small offices to provide internet connectivity. An unauthenticated attacker on the network can reduce the device's wireless transmission power or completely disable its WiFi capabilities, disrupting internet access for all connected users.
Technical details
The vulnerability is a missing authentication check in the setWiFiSignalCfg function within the cstecgi.cgi web interface of TOTOLINK T6. An attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi without providing valid credentials to modify wireless signal configuration. No authentication is required beyond network access to the device's web interface, and the attack can be delivered remotely if the device is accessible from the attacker's network segment. Exploitation allows an attacker to reduce wireless power output or cause a denial of service by disabling WiFi functionality. The vulnerability affects firmware version 4.1.5cu.748_B20211015 and likely other versions.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed