Executive brief
TOTOLINK T6 is a wireless router used in home and small business networks. An unauthenticated attacker on the network can access the router's web interface and retrieve DDNS configuration details, including the domain name, username, and password used to update dynamic DNS services. This allows an attacker to take control of the router's DNS configuration or compromise connected services.
Technical details
The getDdnsCfg function in the router's cstecgi.cgi web interface lacks authentication checks, allowing unauthenticated attackers to send a crafted POST request to /cgi-bin/cstecgi.cgi and retrieve sensitive DDNS configuration data including domain, username, and password. The vulnerability affects TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The attack requires network-level access to the router's web interface but no user interaction or credentials. An attacker can exploit this to extract DDNS credentials and reconfigure DNS settings, potentially redirecting traffic or disrupting service availability.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed