Executive brief
TOTOLINK T6 is a WiFi router used in homes and small offices. An unauthenticated attacker can access a web interface function that lists all WiFi clients connected to the router along with their IP and MAC addresses by sending a simple web request. This information could be used to identify and target specific devices on the network.
Technical details
The vulnerability is an authentication bypass in the getWiFiIpMacTable function exposed via the cstecgi.cgi web interface on TOTOLINK T6 routers. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to retrieve WiFi client MAC-to-IP mappings without requiring valid credentials. The router fails to implement proper access control checks on this sensitive administrative function. The attack is network-accessible and requires no user interaction or authentication.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed