Executive brief
TOTOLINK T6 is a router used to manage network traffic and control user access. The device fails to properly authenticate requests to change browsing policies, allowing an attacker on the network to remotely modify which websites users can access without needing a password. This could disrupt normal business operations and compromise network security.
Technical details
The vulnerability is an authentication bypass (incorrect access control) in the setUrlFilterRules function of the cstecgi.cgi web interface. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to modify URL filtering rules and alter browsing policies. No credentials or prior authentication are required; the attack is network-accessible and can be exploited by any attacker with network connectivity to the device's management interface. The impact is complete compromise of browsing policy controls.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed