Executive brief
TOTOLINK T6 is a WiFi router that provides cloud-based remote control and management capabilities. The device allows unauthenticated attackers to retrieve sensitive cloud configuration and control status information through the web interface, potentially enabling unauthorized device management and service disruption.
Technical details
The getCrpcCfg function in the cstecgi.cgi web interface lacks proper authentication checks, allowing unauthenticated attackers to access cloud remote-control status and URL information. An attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to retrieve sensitive configuration data without valid credentials. This is a missing authentication vulnerability in a CGI endpoint that should require prior authentication before exposing device management capabilities. The attack requires only network access to the device's web interface and no user interaction. Similar unauthenticated information disclosure vulnerabilities exist in multiple other getCrpcCfg-related functions in the same firmware version.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed