Executive brief
The TOTOLINK T6 router's web administration interface contains an authentication bypass vulnerability in the UPnP configuration function. An unauthenticated attacker on the network can retrieve sensitive UPnP settings and port-mapping information without logging in, potentially enabling further network reconnaissance or exploitation.
Technical details
The getUPnPCfg function in the cstecgi.cgi CGI script fails to enforce authentication checks before returning UPnP configuration data. An attacker can craft a POST request to /cgi-bin/cstecgi.cgi with the getUPnPCfg parameter to extract UPnP enablement status and port-mapping information without credentials. The vulnerability requires network access to the router's web interface (typically port 80 or 443). No patch information is currently available for the affected firmware version 4.1.5cu.748_B20211015.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed