Executive brief
TOTOLINK T6 is a wireless router used in homes and small businesses to provide Wi-Fi network access. The device's Wi-Fi access control list (ACL) feature, which manages which devices can connect to the network, can be disabled by unauthenticated attackers sending a crafted request to the device's web interface. This allows anyone with network access to compromise network security by removing access restrictions and allowing unauthorized devices to join.
Technical details
The vulnerability is an authentication bypass and improper access control in the delWiFiAclRules function of the cstecgi.cgi web application on TOTOLINK T6. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to invoke this function without providing valid credentials. The attack is network-reachable and requires no user interaction. An attacker can delete Wi-Fi ACL rules, removing network access restrictions and allowing unauthorized devices to connect to the wireless network. The vulnerability affects firmware version 4.1.5cu.748_B20211015 and likely other versions.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed