TOTOLINK T6 Command Injection Vulnerability in CloudSrvVersionCheck Function

Vulnerability

A critical command injection vulnerability has been identified in the TOTOLINK T6 router, specifically in version 4.1.5cu.748. The issue arises in the CloudSrvVersionCheck function within the /cgi-bin/cstecgi.cgi file, where the 'ip' argument can be manipulated to execute arbitrary commands. This vulnerability can be exploited remotely by sending a malicious HTTP POST request.

Impact

Exploitation of this vulnerability allows for command injection, with the potential for remote code execution.

Reproduction

To reproduce this vulnerability, send a crafted HTTP POST request to the TOTOLINK T6 router's /cgi-bin/cstecgi.cgi endpoint. Include a payload in the 'ip' argument that exploits the command injection flaw. The router must be running firmware version 4.1.5cu.748.

Added: Jul 14, 2025, 3:23 PM
Updated: Jul 14, 2025, 3:23 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
9.1
remediation
0.0
relevance
0.2
threat
6.5
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.