Executive brief
TOTOLINK T6 is a wireless router used for home and small business networking. The device's configuration interface contains a flaw that allows attackers on the network to retrieve sensitive access-device policies and connected client information without providing login credentials, potentially enabling network reconnaissance and unauthorized access planning.
Technical details
The getAccessDeviceCfg function in the cstecgi.cgi CGI script fails to properly validate user authentication before processing requests. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to invoke this function and retrieve access-device policy configuration and client state information. No authentication is required and the function is network-accessible. This is an authentication bypass / missing access control vulnerability (CWE-306). Exploitation requires only network reachability to the device's web interface on the LAN.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed