Executive brief
TOTOLINK T6 is a network device used to provide internet connectivity and cloud-based remote management. An attacker can bypass authentication to retrieve sensitive cloud remote-control configuration including status and control URLs. This allows an unauthenticated attacker to obtain information needed to potentially take control of the device remotely or further compromise network operations.
Technical details
The vulnerability is an authentication bypass in the getCrpcConfig function exposed via the cstecgi.cgi endpoint. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to retrieve cloud remote-control (CRPC) configuration data including status information and URLs. The vulnerable function fails to properly validate the user's authentication status before returning sensitive configuration data. Attack requires only network reachability to the device's web interface and no authentication credentials. No patch information is currently available in the advisory.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed