Executive brief
TOTOLINK T6 is a residential wireless router used for network connectivity. An authentication bypass flaw allows unauthenticated attackers to retrieve recent system logs by sending a specially crafted request to the router's web interface. This exposes sensitive system information that could aid further attacks on the device or connected network.
Technical details
The vulnerability is an incorrect access control flaw in the showSyslog function of the cstecgi.cgi web interface on TOTOLINK T6 firmware 4.1.5cu.748_B20211015. Unauthenticated attackers can send a crafted POST request to /cgi-bin/cstecgi.cgi to retrieve recent system logs without authentication. The vulnerability allows network-based unauthorized information disclosure. No patch availability is mentioned in the advisory.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed