Executive brief
TOTOLINK T6 is a residential router/gateway device used to provide network connectivity and storage management features. An unauthenticated attacker on the network can query the device's storage configuration settings via a crafted POST request, exposing internal system state that should remain private.
Technical details
This vulnerability is a missing authentication (incorrect access control) issue in the getStorageCfg function within the cstecgi.cgi web interface of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An attacker can send a specially crafted POST request to /cgi-bin/cstecgi.cgi to retrieve storage feature state information without providing authentication credentials. The attack requires only network access to the device's web interface; no user interaction is needed. While not remotely exploitable from the internet in most home networks (due to NAT), it poses a risk in environments where the device is directly exposed or accessible via local network. No patch status is available in the advisory text.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed