Executive brief
TOTOLINK T6 is a home router used to provide network connectivity and traffic management. An unauthenticated attacker on the network can send a crafted HTTP request to disable or degrade the router's Quality of Service (QoS) traffic shaping features, affecting the performance and reliability of the network for all connected devices.
Technical details
The vulnerability is an authentication bypass in the setSmartQosCfg function of TOTOLINK T6 version 4.1.5cu.748_B20211015. The vulnerable CGI endpoint at /cgi-bin/cstecgi.cgi fails to enforce access control, allowing any network-connected attacker to invoke privileged operations without authentication. An attacker can craft a malicious POST request to modify QoS configuration settings, disabling traffic management policies. The attack requires network reachability to the router's web interface but no prior authentication or user interaction. A patch or firmware update is recommended.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed