Executive brief
TOTOLINK T6 is a network access device used in ISP and enterprise deployments. An unauthenticated attacker can retrieve sensitive device configuration information by sending a crafted request to the web interface, potentially exposing network settings, WiFi credentials, and system details that could enable further attacks.
Technical details
The getInitCfg function in the cstecgi.cgi web interface lacks proper authentication checks, allowing unauthenticated POST requests to retrieve sensitive device configuration data. The vulnerability exists in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An attacker on the network (or with network access to the device's web interface) can exploit this via a simple POST request to /cgi-bin/cstecgi.cgi without credentials, obtaining initialization configuration including WiFi settings, network parameters, and system information. No patch information is currently available in the advisory.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed