Executive brief
TOTOLINK T6 is a residential WiFi router that manages internet connectivity and network configuration. An unauthenticated attacker can change the device's operating mode by sending a crafted request, potentially disrupting network services, redirecting traffic, or modifying critical device behavior without requiring any authentication or special access.
Technical details
The vulnerability is an access control bypass (CWE-306) in the setOpModeCfg function of the cstecgi.cgi web interface. The affected component fails to authenticate requests before allowing modifications to the device operating mode. An unauthenticated attacker can send a POST request to /cgi-bin/cstecgi.cgi to invoke setOpModeCfg and change the device's operational state. The attack is network-reachable and requires no authentication or user interaction. This allows remote attackers to modify device configuration and potentially render the router unusable or redirect its behavior to attacker-controlled specifications. Patch information has not been disclosed.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed