Executive brief
TOTOLINK T6 is a wireless router that manages network connectivity and roaming behavior for connected devices. An unauthenticated attacker on the network can modify roaming settings by sending crafted requests to the device's web interface, potentially disrupting wireless connectivity or redirecting device traffic.
Technical details
The vulnerability is an access control bypass in the setRoamingCfg function of the router's CGI interface (/cgi-bin/cstecgi.cgi). The function fails to require authentication before accepting configuration changes, allowing any network-reachable attacker to submit POST requests that alter roaming behavior. The attack requires no authentication or user interaction; attackers can directly craft malicious POST payloads to modify roaming settings. This is part of a broader pattern of missing authentication controls in the TOTOLINK T6 firmware. Patches or firmware updates may be available from TOTOLINK.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed