Executive brief
The TOTOLINK T6 router's web interface contains a missing authentication check that allows any unauthenticated attacker on the network to retrieve firewall filtering rules via a simple web request. By exploiting this vulnerability, an attacker can enumerate network security policies and identify filtering rules, potentially discovering how the network is configured and which traffic is restricted. This exposes sensitive network architecture and security posture to unauthorized parties without requiring any login credentials.
Technical details
This vulnerability is an authentication bypass in the getIpPortFilterRules CGI function within the TOTOLINK T6 router's cstecgi.cgi web interface. The affected firmware version is 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to retrieve IP and port filtering rules, as the function fails to validate user authentication before processing the request. The attack requires only network reachability to the router's web interface (typically HTTP/HTTPS on port 80/443) and no user interaction. An attacker can leverage this to enumerate firewall configurations and understand network security policies. A patch status is not indicated in the available references.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed