Executive brief
The TOTOLINK T6 router contains an authentication bypass vulnerability in its QoS (Quality of Service) configuration function. An attacker on the network can remove or disable traffic management rules without any credentials, disrupting network performance controls and potentially allowing malicious traffic to bypass intended restrictions.
Technical details
The delSmartQosCfg function in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 fails to enforce authentication checks before processing configuration deletion requests. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi with the appropriate function parameter to delete QoS rules. The vulnerability is accessible over the network to any attacker who can reach the router's web interface. Successful exploitation allows complete removal of Smart QoS configurations, degrading network performance management. No patch status is confirmed in available documentation.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed