Executive brief
TOTOLINK T6 is a wireless router that manages firmware updates and system configuration. An unauthenticated attacker can exploit missing access controls in the upload functionality to manipulate firmware or system files, potentially leading to unauthorized system modification, malware installation, or device takeover.
Technical details
The vulnerability is an incorrect access control issue in the setUploadSetting function of the cstecgi.cgi CGI application. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to bypass authentication and manipulate the upload or flash workflow. The vulnerability is network-reachable and requires no authentication or user interaction. A successful exploit allows an attacker to alter firmware updates, flash custom code, or modify system configurations, potentially achieving remote code execution or permanent device compromise.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed