Executive brief
TOTOLINK T6 is a router used to provide network connectivity and manage internet traffic in homes and small offices. An unauthenticated attacker can remotely send a crafted request to the router's web interface and obtain sensitive port-forwarding configuration rules without any credentials, potentially exposing network access patterns and enabling further attacks.
Technical details
The getPortForwardRules function in the TOTOLINK T6 router firmware (version 4.1.5cu.748_B20211015) lacks proper authentication checks, allowing unauthenticated attackers to retrieve port-forwarding rules. The vulnerable endpoint is accessible via a POST request to /cgi-bin/cstecgi.cgi without requiring valid session credentials. An attacker on the network (or with network access to the router) can invoke this function to obtain port-forwarding configuration, which typically includes internal IP addresses, forwarded ports, and destination services. This is one of multiple authentication bypass vulnerabilities identified in the same firmware version affecting various CGI functions. No patch availability is currently indicated in the advisory.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed