Executive brief
TOTOLINK T6 is a residential router used to provide internet connectivity and network configuration. An unauthenticated attacker can send a crafted web request to retrieve the router's LAN address and DHCP configuration, potentially exposing sensitive network settings and enabling further attacks on the local network.
Technical details
The getLanCfg function in the cstecgi.cgi web interface fails to enforce authentication checks before processing requests. An attacker can send an HTTP POST request to /cgi-bin/cstecgi.cgi without credentials to retrieve LAN addressing and DHCP configuration information. No authentication or special privileges are required; the attack is over the network from any system that can reach the web interface. This exposure of network configuration can facilitate reconnaissance for subsequent attacks.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed