Executive brief
TOTOLINK T6 is a residential router used to provide internet connectivity and network management. An unauthenticated attacker can send a malicious request to the web interface to erase traceroute logs, allowing an attacker to cover their tracks after reconnaissance or other malicious network activity on the device.
Technical details
The vulnerability is an incorrect access control issue in the clearTracerouteLog function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The function is exposed via the /cgi-bin/cstecgi.cgi endpoint and lacks authentication checks, allowing unauthenticated attackers to delete traceroute logs by sending a crafted POST request. The attack vector is network-based with no user interaction required. An attacker can exploit this to erase system logs and cover evidence of network reconnaissance or other malicious activities performed on the device.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed