Executive brief
The TOTOLINK T6 router contains a missing authentication vulnerability in its web management interface. An unauthenticated attacker can remotely erase system diagnosis logs by sending a crafted request, potentially destroying evidence of prior system activity or compromising troubleshooting capabilities.
Technical details
This is an authentication bypass vulnerability in the clearDiagnosisLog function of the cstecgi.cgi CGI script. The affected component fails to validate user authentication before processing requests to erase diagnostic logs. An unauthenticated attacker on the network can exploit this by sending a crafted POST request to /cgi-bin/cstecgi.cgi without credentials. The vulnerability allows deletion of diagnostic logs that would normally require administrative access, potentially hindering incident response and troubleshooting. TOTOLINK has been notified of this and related authentication bypass issues across multiple functions in the same codebase.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-09-01: disclosed