Executive brief
TOTOLINK T6 is a home/small-business WiFi router that stores operational logs and system settings. This vulnerability allows an unauthenticated attacker on the network to retrieve sensitive syslog configuration details by sending a single web request, potentially exposing diagnostic information and system settings that should be restricted to authorized administrators.
Technical details
The vulnerability is an authentication bypass in the getSyslogCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The vulnerable CGI endpoint /cgi-bin/cstecgi.cgi fails to properly validate user credentials before processing requests for syslog configuration. An unauthenticated attacker on the network can craft a POST request to this endpoint to retrieve syslog-related configuration without providing valid login credentials. No CVSS vector details are available in the advisory, though the reported CVSS score is 9.1 (critical). A patch status is not mentioned in the provided materials.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed