Executive brief
The TOTOLINK T6 is a router that manages network and device configuration. This vulnerability allows an unauthenticated attacker to access sensitive diagnostic configuration and ping logs by sending a specially crafted request to the web interface, potentially exposing network topology, system settings, and diagnostics that should require administrator credentials.
Technical details
The getDiagnosisCfg function in the cstecgi.cgi CGI script lacks proper authentication checks, allowing unauthenticated users to retrieve diagnostic configuration and ping log contents. An attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi without authentication credentials to trigger this function and access sensitive data. No special network positioning or user interaction is required—any remote attacker with network access to the device's web interface can exploit this. The vulnerability exposes operational diagnostics and configuration that could aid in further network reconnaissance or attacks. Patch status is not indicated in the advisory.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed