Horizon Alert
Summary of the vulnerability and why it matters
This advisory addresses a critical vulnerability discovered in TOTOLINK T6 routers. An attacker could exploit this issue to remotely reconfigure devices, potentially disrupting network operations. The main concern is confirming if this specific router model is in use and, if so, determining its exposure.
- Unauthenticated attackers can force router reboots.
- Affects edge network devices, potentially impacting availability.
- Confirm usage and exposure; understand potential disruption.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can trigger a forced reboot on a TOTOLINK router by sending a specially crafted request to the device's web interface. This allows the attacker to disrupt the router's operation without needing any prior access or credentials. The vulnerability resides within the `setScheduleCfg` function, which incorrectly handles access control for configuring reboot tasks.
- No authentication required for access.
- Triggered by a POST request to a CGI script.
- Risk of device disruption and availability loss.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability allows unauthenticated attackers to configure forced reboot tasks on TOTOLINK routers. When supported by the advisory, this could affect the device's availability and potentially allow unauthorized configuration changes.
- Router availability could be impacted.
- Unauthenticated requests could trigger reboots.
- Service disruption and unauthorized changes.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in TOTOLINK routers impacts devices exposed to the network, likely affecting customers managing their own home or small business networks. The first practical step is to identify all instances of the affected product, determine their internet reachability and criticality, and then coordinate with the vendor for a permanent fix.
- Identify affected device owners.
- Verify external reachability first.
- Plan vendor-coordinated remediation.