Executive brief
TOTOLINK T6 is a home/small-office router that manages network traffic and port forwarding. This vulnerability allows unauthenticated attackers to delete port-forwarding rules via the web interface, disrupting legitimate network traffic routing and potentially exposing the network to intrusion by eliminating security controls.
Technical details
The vulnerability is an improper access control flaw in the delPortForwardRules function of cstecgi.cgi, a web administration interface on TOTOLINK T6. Affected versions prior to 4.1.5cu.748_B20211015 do not properly authenticate requests before processing port-forwarding rule deletion. An unauthenticated attacker on the network can craft a POST request to /cgi-bin/cstecgi.cgi and delete port-forwarding rules without credentials, resulting in service disruption and potential network misconfiguration. The attack requires network access but no user interaction or authentication.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015 and earlier
Timeline
- 2026-08-31: disclosed