Executive brief
The TOTOLINK T6 wireless router lacks proper authentication checks in its getDdnsStatus function, allowing unauthenticated users on the network to retrieve sensitive information about the router's dynamic DNS status and public IP address. An attacker can exploit this by sending a specially crafted request to the router's web interface, potentially gathering reconnaissance data for further attacks.
Technical details
The vulnerability is an authentication bypass (missing access control) in the getDdnsStatus function within the cstecgi.cgi endpoint of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi without providing valid credentials to retrieve the DDNS runtime status and public IP information. The attack requires network access to the router's web interface (typically on the LAN or WAN if exposed), but no prior authentication or user interaction. The exposed data could aid further reconnaissance or social engineering attacks. A patch availability status is not specified in the advisory.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed