Executive brief
TOTOLINK T6 is a home router device that manages network settings and DHCP (Dynamic Host Configuration Protocol) reservations. An unauthenticated attacker can send a specially crafted request to retrieve sensitive static DHCP reservation rules, which may include device IP assignments and network configuration details. This allows an attacker to gather information about the network structure without needing administrator credentials.
Technical details
The getStaticDhcpRules function in the cstecgi.cgi CGI script on TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 lacks authentication checks, allowing unauthenticated attackers to access static DHCP reservation configuration. An attacker can send an unauthenticated POST request to /cgi-bin/cstecgi.cgi with the getStaticDhcpRules function parameter to retrieve DHCP reservation rules. This is a broken access control vulnerability affecting an information disclosure function. No authentication bypass or exploitation complexity is required—the function is directly callable over the network. A patch status has not been publicly disclosed.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed