Executive brief
TOTOLINK T6 is a residential WiFi router that includes parental control features to restrict device access. An unauthenticated attacker can remove parental control rules by sending a specially crafted request to the router's web interface, effectively disabling safety protections without user knowledge or authorization.
Technical details
The vulnerability is an incorrect access control flaw in the delParentalRules function within the cstecgi.cgi endpoint. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to delete parental control rules without requiring valid authentication credentials. The router does not properly validate the request source, allowing network-based attackers to disable parental controls remotely. No patches are known to be available for the affected version 4.1.5cu.748_B20211015.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed