Executive brief
TOTOLINK T6 is a WiFi router with parental control features. An unauthenticated attacker can send a specially crafted web request to disable or modify parental control settings, allowing access to restricted content or removing supervision on child accounts without the administrator's knowledge or consent.
Technical details
The vulnerability is an incorrect access control flaw in the setParentalRules function of the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. The affected CGI endpoint at /cgi-bin/cstecgi.cgi does not properly authenticate incoming POST requests before allowing modification of parental control rules. An unauthenticated, network-adjacent attacker can craft and send a POST request to this endpoint to alter parental control behavior. The vulnerability requires network access to the router but no authentication credentials. Patches or vendor guidance is not mentioned in the advisory.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed