Executive brief
TOTOLINK T6 is a residential router that manages network configuration and time synchronization. An unauthenticated attacker can retrieve sensitive NTP configuration and current time data by sending a crafted request to the router's web interface, potentially enabling network-based attacks or credential harvesting that depend on accurate time.
Technical details
The vulnerability is an authentication bypass in the getNtpCfg function exposed via the /cgi-bin/cstecgi.cgi endpoint on TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated POST requests to retrieve NTP configuration and system time data without any access control checks. An attacker on the network can reach this endpoint remotely without credentials or user interaction. Exploitation reveals sensitive timing and configuration details that could facilitate further attacks. The advisory indicates this is part of a pattern of missing authentication in multiple cstecgi.cgi functions in the same firmware version.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed