Executive brief
TOTOLINK T6 is a residential router that manages network traffic filtering and security settings. An unauthenticated attacker can access the device's DMZ (demilitarized zone) configuration through a web interface flaw, allowing them to learn sensitive network topology information without logging in. This could enable follow-up attacks on exposed systems or network reconnaissance.
Technical details
The vulnerability is an authentication bypass in the getUrlFilterRules function of cstecgi.cgi on TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to retrieve DMZ configuration information that should require administrative authentication. The attack is remotely exploitable without user interaction via the network-accessible web management interface. No patch availability is currently indicated in the advisory.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed