Executive brief
TOTOLINK T6 is a residential router used to connect devices to the internet and manage home networking. An unauthenticated attacker on the network can access the setup wizard and onboarding configuration through a missing authentication check, allowing them to view sensitive router configuration details without a password.
Technical details
This vulnerability is an authentication bypass in the getWizardCfg function of cstecgi.cgi on TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The affected CGI script fails to validate authentication before processing POST requests, allowing any network-connected attacker to retrieve setup wizard and onboarding configuration information without credentials. The attack requires only network access to the router's web interface (/cgi-bin/cstecgi.cgi) and no user interaction. An attacker can obtain configuration details that may include network settings, device information, and other setup parameters. No patch status information is currently available in the advisory.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed