Executive brief
The TOTOLINK T6 router is used to provide internet connectivity and network management for home and small office networks. An unauthenticated attacker on the network can bypass access controls and modify MAC address filtering rules, allowing them to change which devices are permitted or denied network access. This could enable an attacker to grant themselves network access, isolate other devices, or disrupt network connectivity for legitimate users.
Technical details
The vulnerability is an authentication bypass in the setMacFilterRules function of the cstecgi.cgi endpoint running on TOTOLINK T6 version 4.1.5cu.748_B20211015. An attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi without authentication credentials to modify device MAC address filtering rules. This allows an unauthenticated attacker on the network to change access control lists, potentially grant themselves network access, or deny access to other devices. No authentication or user interaction is required beyond network connectivity to the router.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed