Executive brief
TOTOLINK T6 is a residential router/gateway device that manages internet connectivity and network configuration. An unauthenticated attacker can send a specially crafted web request to alter upstream network provisioning settings, potentially disrupting internet service, redirecting traffic, or causing service outages for all connected users.
Technical details
The vulnerability is a missing authentication check (CWE-306) in the setWanCfg function of the cstecgi.cgi CGI script. An attacker can send an unauthenticated POST request to /cgi-bin/cstecgi.cgi to modify WAN (Wide Area Network) configuration parameters. The attack requires network reachability to the router's web interface (typically on the local network or exposed to the internet). Successful exploitation allows an attacker to reconfigure upstream connectivity settings without any authentication, potentially causing service disruption or enabling further network attacks. No patch information is currently available.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed