Executive brief
TOTOLINK T6 is a WiFi router that manages network connectivity for homes and small businesses. An unauthenticated attacker can trigger WAN (wide-area network) discovery logic by sending a specially crafted request to the router's web interface, potentially disrupting network operations or gathering sensitive network configuration details without any credentials.
Technical details
The vulnerability is an authentication bypass / missing access control flaw in the discoverWan function within the cstecgi.cgi web interface handler of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated remote attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to invoke the discoverWan function, which should have been protected with authentication checks. The router is network-accessible from the internet or local network by default, and no user interaction or credentials are required. An attacker can abuse this to trigger WAN discovery operations, potentially exposing configuration data or disrupting WAN connectivity. The advisory does not indicate patch availability at the time of publication.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-09-01: disclosed