Executive brief
The TOTOLINK T6 router is a wireless networking device used to provide internet connectivity and network management. An unauthenticated attacker can access the router's traceroute diagnostic logs without providing any credentials by sending a crafted request, exposing sensitive network diagnostic information that could be used to map network infrastructure.
Technical details
The vulnerability is an authentication bypass (missing access control) in the getTracerouteCfg function within the cstecgi.cgi web interface of TOTOLINK T6firmware 4.1.5cu.748_B20211015. The function fails to validate user authentication before processing traceroute configuration requests. An attacker can send an unauthenticated POST request to /cgi-bin/cstecgi.cgi with the appropriate function parameter to retrieve traceroute diagnostic logs. No authentication credentials or special preconditions are required; the vulnerability is network-accessible. The impact is information disclosure of network diagnostic data.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed