Executive brief
TOTOLINK T6 is a wireless router used to provide internet connectivity in homes and small offices. An unauthenticated attacker on the network can retrieve sensitive LAN and DHCP configuration details by sending a crafted request to the router's web interface, potentially enabling further network reconnaissance or reconfiguration attacks.
Technical details
The vulnerability is an authentication bypass (missing access control) in the getWanIeCfg function within the cstecgi.cgi web interface handler. An unauthenticated attacker can send a POST request to /cgi-bin/cstecgi.cgi to invoke this function and retrieve LAN addressing and DHCP configuration information that should only be accessible to authenticated administrators. The vulnerability requires network access to the router's management interface but no authentication credentials. Exploitation allows an attacker to obtain network configuration details that could facilitate network mapping, DHCP manipulation, or further attacks.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed