Executive brief
TOTOLINK T6 is a Wi-Fi repeater device used to extend network coverage in homes and offices. An unauthenticated attacker can exploit missing access controls to redirect the device to connect to an attacker-controlled Wi-Fi network instead of the legitimate upstream network, effectively hijacking the device's connectivity and potentially intercepting traffic or launching further attacks.
Technical details
The setWiFiRepeaterCfg function in cstecgi.cgi lacks proper authentication and access control checks. An attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi without credentials to reconfigure the device's Wi-Fi repeater settings, allowing redirection to a malicious upstream network. The vulnerability requires network access to the device's web interface but no prior authentication. Successful exploitation allows an attacker to modify critical network configuration, potentially intercepting all traffic passing through the repeater or using it as a pivot point for further network attacks.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed