Executive brief
The TOTOLINK T6 is a wireless router used to manage network connectivity and security settings. A vulnerability in the router's web interface allows unauthenticated attackers to remove MAC address filtering rules, which could allow unauthorized devices to bypass network access controls and connect to the router's network.
Technical details
This vulnerability is an incorrect access control flaw in the delMacFilterRules function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to delete MAC filter rules without authentication. MAC filtering is a security mechanism that restricts network access to devices with approved MAC addresses; removal of these rules allows any device to connect to the network. The vulnerability requires only network access to the router's web interface—no authentication or user interaction is needed. A patch or firmware update from TOTOLINK is the recommended remediation.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed