Executive brief
TOTOLINK T6 is a wireless router used to provide network connectivity in homes and small offices. The device's web interface contains an unauthenticated function that reveals which clients are currently connected to the network, allowing an attacker to gather information about active devices without any credentials. An attacker on the same network could use this information to identify targets for further compromise.
Technical details
The getOnlineClient function in the cstecgi.cgi web interface on TOTOLINK T6 4.1.5cu.748_B20211015 fails to enforce authentication before processing requests. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to retrieve a list of online client devices and their information. The vulnerability requires network reachability to the router's web interface but no prior authentication or user interaction. This missing authentication check allows information disclosure about connected devices, which can be used to enumerate network resources for subsequent attacks.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed