Executive brief
The TOTOLINK T6 router's web management interface lacks proper authentication checks on the Wi-Fi scheduling configuration deletion function. An attacker on the network can send a crafted request to disable Wi-Fi schedules without logging in, disrupting network access controls that the device administrator has configured.
Technical details
This vulnerability is an incorrect access control flaw in the delWiFiScheduleCfg function exposed via the /cgi-bin/cstecgi.cgi endpoint on TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The function fails to verify authentication before processing requests to delete Wi-Fi schedule entries. An unauthenticated attacker with network access can send a POST request to trigger deletion of Wi-Fi scheduling configurations. No special credentials, user interaction, or authentication are required. The impact is limited to tampering with Wi-Fi schedule settings rather than code execution or broader system compromise. Patches or firmware updates addressing this issue are not mentioned in the available advisory information.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed