CVE-2025-7862
7.3TOTOLINK · T6
A missing authentication vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to enable the Telnet service via the cstecgi.cgi script.
Executive summary
A critical authentication bypass vulnerability in TOTOLINK T6 routers allows remote, unauthenticated attackers to enable the Telnet service and potentially gain unauthorized system access.
Vulnerability
This flaw exists within the setTelnetCfg function of the /cgi-bin/cstecgi.cgi file, where the application fails to perform necessary capability checks. An unauthenticated attacker can remotely trigger this function via HTTP POST or MQTT packets to enable the Telnet service, which provides a path toward further system compromise.
Business impact
The ability for an unauthenticated remote attacker to enable Telnet on a networking device poses a severe risk to organizational infrastructure. By bypassing authentication, attackers can facilitate unauthorized access, potentially leading to full device takeover, traffic interception, or pivot points into internal networks. The CVSS score of 7.3 reflects the high risk associated with remote exploitability, despite the partial impact on confidentiality, integrity, and availability.
Remediation
Immediate Action: As no specific patch version is currently identified, users should immediately disable the Telnet service if it has been enabled and restrict access to the device management interface to trusted internal networks only.
Proactive Monitoring: Security teams should monitor network traffic for anomalous HTTP POST requests directed at /cgi-bin/cstecgi.cgi or unauthorized MQTT traffic on port 1883.
Compensating Controls: Deploy a Web Application Firewall (WAF) or network access control list (ACL) to block external access to the device management interface and the identified vulnerable endpoint.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists in the form of a researcher-provided technical write-up on GitHub.
Analyst recommendation
Given the availability of public proof-of-concept code and the ease of exploitation, this vulnerability requires immediate attention. Administrators must ensure that the management interfaces of TOTOLINK T6 devices are not exposed to the public internet and should monitor for any signs of unauthorized Telnet activation. Apply firmware updates from the vendor as soon as they become available to permanently resolve the underlying authentication failure.
More TOTOLINK CVEs
Sources
Originally found and disclosed by reisen_1943 (VulDB User), per the CVE Program record.
- VDB-316975 | TOTOLINK T6 Telnet Service cstecgi.cgi setTelnetCfg missing authentication Vulnerability database entry
- VDB-316975 | CTI Indicators (IOB, IOC, IOA)
- Submit #617643 | TOTOLINK T6 V4.1.5cu.748_B20211015 Missing Authentication Third-party advisory
- Related
- Exploit / PoC
- youtube.com
- totolink.net