Executive brief
TOTOLINK T6 is a residential router used to provide network connectivity and security. An authentication bypass vulnerability in its web interface allows unauthenticated attackers to retrieve sensitive VPN pass-through and WAN ping filter settings by sending a crafted request, potentially enabling network reconnaissance or unauthorized configuration changes.
Technical details
The vulnerability is an authentication bypass (CWE-306) in the getVpnPassCfg function within the /cgi-bin/cstecgi.cgi endpoint of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The affected CGI handler fails to perform authentication checks before processing requests, allowing any unauthenticated remote attacker to send a POST request and retrieve VPN passthrough configuration and WAN ping filter settings. The attack requires only network reachability to the router's web interface and no user interaction. This is part of a broader pattern of authentication bypass vulnerabilities in this firmware version affecting multiple CGI functions.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed