Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in TOTOLINK routers that could allow unauthenticated attackers to bypass parental control settings by sending a malicious request. The issue lies within the router's access control, potentially enabling unauthorized modification of network rules without needing to log in. The main concern is confirming if this type of device and its specific function are in use within our environment.
- Attackers can remove parental controls remotely.
- Affects internet edge devices, potentially exposing networks.
- Confirm relevance and exposure within your environment.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can exploit this vulnerability by sending a specially crafted request to the device's web interface. This request targets a specific function that improperly handles access controls, allowing the attacker to bypass normal security checks and modify parental control settings. When successful, this could allow an attacker to remove existing parental control rules.
- Attacker sends crafted POST request.
- Accesses vulnerable parental control function.
- Allows removal of parental rules.
Live Threat
Current exploitation, exposure, and threat context
An unauthenticated attacker could remove parental-control rules by sending a specially crafted request to the device. This could allow bypassing network access restrictions that were previously configured.
- Parental-control rules.
- Attacker sends crafted POST request.
- Bypasses network access restrictions.
Operational Fix
Recommended remediation, mitigation, and detection steps
The TOTOLINK T6 router's parental control functionality is vulnerable due to improper access controls, allowing unauthenticated attackers to remove rules via a crafted POST request. This critical vulnerability, exploitable over the network, requires immediate attention from teams responsible for network edge devices and device management. The first practical step is to identify all deployed T6 routers, confirm their network exposure and business criticality, and then coordinate with the vendor and relevant internal teams to plan remediation.
- Network and device management teams should own this.
- Verify external exposure and business criticality.
- Coordinate with the vendor for a fix.