Executive brief
TOTOLINK T6 is a consumer WiFi router that manages network connectivity and device access control. An unauthenticated attacker can query the router's Telnet service configuration status through a crafted web request, potentially identifying when Telnet is enabled and using that information for further compromise of the device's management interface.
Technical details
The getTelnetCfg function in cstecgi.cgi lacks proper authentication checks, allowing an unauthenticated POST request to /cgi-bin/cstecgi.cgi to retrieve Telnet enablement status. The vulnerable function is reachable over the network without credentials. While the information disclosed is limited to service status, it can serve as reconnaissance for attacks targeting the Telnet service itself or as part of a multi-stage compromise. A patch addressing this authentication bypass has been disclosed but adoption status is unknown.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed