Executive brief
The TOTOLINK T6 router's parental control management interface lacks proper authentication checks, allowing unauthenticated users on the network to retrieve parental-control configuration rules. An attacker could obtain complete visibility into the router's content filtering and usage monitoring settings, potentially identifying bypass techniques or learning patterns about what content families are attempting to block.
Technical details
This is an authentication bypass vulnerability in the getParentalRules function of the TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. The vulnerable endpoint (/cgi-bin/cstecgi.cgi) fails to validate user authentication before processing crafted POST requests, allowing unauthenticated network-adjacent attackers to retrieve sensitive parental-control configuration data. No special privileges, credentials, or user interaction are required; an attacker on the same network can directly invoke the function to extract rules. The vulnerability exposes configuration that should be admin-only, leading to information disclosure of security policy settings.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed