Executive brief
TOTOLINK T6 routers contain an access control vulnerability in the WiFi WPS (WiFi Protected Setup) status function that allows unauthenticated attackers to retrieve wireless configuration and WPS runtime status. An attacker on the network can query this sensitive information without credentials, potentially exposing the device configuration and wireless setup details needed to compromise network security.
Technical details
The vulnerability is a missing authentication check in the getWiFiWpsStatus function of the cstecgi.cgi web interface in TOTOLINK T6 version 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to retrieve WiFi WPS runtime status and configuration without providing valid credentials. This is a network-accessible information disclosure vulnerability that requires no user interaction. The root cause is improper access control logic that fails to verify authentication before processing the request.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed