Executive brief
TOTOLINK T6 is a wireless router used to provide internet connectivity to homes and offices. An unauthenticated attacker can obtain the MAC address of connected WiFi clients by sending a specially crafted request to the router's web interface, enabling device enumeration and network reconnaissance without any credentials.
Technical details
The getStationMacByIp function in the cstecgi.cgi CGI script lacks proper authentication checks, allowing unauthenticated POST requests to retrieve client MAC addresses. The vulnerability exists in the web management interface accessible at /cgi-bin/cstecgi.cgi. An attacker on the network can send a crafted POST request to extract MAC address information for any connected client, facilitating network mapping and targeted attacks. No authentication or special privileges are required to exploit this vulnerability.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed