Executive brief
TOTOLINK T6 is a wireless router used in residential and small business networks. An unauthenticated attacker on the network can send a specially crafted request to disable or alter the router's Wi-Fi schedule, causing potential service disruption and loss of network availability control.
Technical details
The vulnerability is an incorrect access control flaw in the setWiFiScheduleCfg function within the cstecgi.cgi CGI script. An attacker can send an unauthenticated POST request to /cgi-bin/cstecgi.cgi to modify Wi-Fi scheduling configurations. The vulnerability requires network access to the router's administration interface but no authentication credentials. Successful exploitation allows an attacker to alter when the Wi-Fi radio is available, disrupting network connectivity without authorization. No information on patch availability is provided in the advisory.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed