Executive brief
TOTOLINK T6 is a residential router/gateway device. An unauthenticated attacker can reconfigure primary Wi-Fi settings (such as SSID and password) without any authentication, by sending a crafted request to the device's web administration interface. This allows an attacker to lock legitimate users off the network and redirect traffic through a modified access point.
Technical details
The vulnerability is an access control flaw (CWE-284) in the setWiFiBasicCfg function of the cstecgi.cgi CGI script. The function fails to require authentication before allowing Wi-Fi configuration changes. An attacker can send an HTTP POST request to /cgi-bin/cstecgi.cgi from the network to modify primary Wi-Fi parameters. No authentication credentials, session token, or user interaction is required. The attack is possible from any device with network access to the router (e.g., through an open Wi-Fi network or downstream LAN device). No patch status is publicly documented.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed