Executive brief
The TOTOLINK T6 router contains an authentication bypass vulnerability in its web-based management interface. An unauthenticated attacker can retrieve sensitive wireless configuration settings by sending a specially crafted request, potentially exposing network passwords, encryption keys, and SSID information without requiring login credentials.
Technical details
The getWiFiAdvancedCfg function in cstecgi.cgi lacks proper authentication checks, allowing unauthenticated POST requests to retrieve advanced Wi-Fi configuration data. The vulnerability is triggered by sending a crafted POST request to /cgi-bin/cstecgi.cgi without authentication. An attacker with network access to the router can exploit this to extract sensitive wireless settings including SSID, encryption type, and potentially pre-shared keys. The vulnerability affects TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 and represents a missing authentication control issue.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed