Executive brief
TOTOLINK T6 is a residential WiFi router. An unauthenticated attacker can send a specially crafted request to alter the wireless availability schedule, potentially disabling or restricting internet access to connected devices without authorization.
Technical details
The setApWiFiSchCfg function in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 lacks proper authentication checks. An attacker can send an unauthenticated POST request to /cgi-bin/cstecgi.cgi to modify wireless scheduling parameters, altering when the WiFi is available. The vulnerability requires network access to the device's web interface but does not require authentication or user interaction. An attacker can modify wireless availability windows, potentially disrupting network access for legitimate users.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed