Executive brief
TOTOLINK T6 is a wireless router used in home and small business networks. An unauthenticated attacker can modify the device's Wi-Fi schedule configuration by sending a crafted request to the web interface, allowing them to disable or alter Wi-Fi scheduling rules without any authentication credentials.
Technical details
The FirmwareUpgrade function in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 lacks proper access control validation, allowing unauthenticated attackers to modify device settings. The vulnerability exists in the /cgi-bin/cstecgi.cgi endpoint, which accepts POST requests without verifying the caller's authentication status. An attacker on the network can send a crafted POST request to remove or modify Wi-Fi schedule entries, causing service disruption. The vulnerability requires network access to the router's web interface but no user interaction or credentials. A patch or updated firmware version may be available from TOTOLINK.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed