Executive brief
The TOTOLINK T6 router contains an authentication bypass vulnerability in the cloud firmware check feature. An unauthenticated attacker on the network can obtain sensitive cloud server status information by sending crafted requests to the device's web interface, potentially exposing firmware update infrastructure details that could be leveraged for further attacks.
Technical details
This is an authentication bypass (incorrect access control) vulnerability in the getCloudSrvCheckStatus function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The vulnerable component is accessible via HTTP POST requests to /cgi-bin/cstecgi.cgi. An unauthenticated attacker with network access to the router can invoke this function without providing valid credentials, allowing them to retrieve cloud firmware check status information. No user interaction is required. The vulnerability can be remedied through a firmware update that adds proper authentication checks to the function.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed