Executive brief
TOTOLINK T6 is a wireless router used in homes and small businesses to provide internet connectivity and network management. An unauthenticated attacker can remotely erase system logs by sending a specially crafted request, enabling an attacker to hide traces of malicious activity or system compromise.
Technical details
This vulnerability is an authentication bypass in the clearSyslog function within the cstecgi.cgi web interface component of TOTOLINK T6 firmware. An unauthenticated attacker can send a POST request to /cgi-bin/cstecgi.cgi to trigger the clearSyslog function and erase system logs. The router's management interface fails to properly validate user authentication before allowing this sensitive operation. The attack requires network access to the router's web interface (typically port 80 or 443) but no authentication credentials. This allows attackers to cover their tracks after compromising the device or performing reconnaissance.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed