TOTOLINK T6 formLoginAuth.htm Form_Login missing authentication

CVE Details

Basic Information

Title TOTOLINK T6 formLoginAuth.htm Form_Login missing authentication
Type cve
Published 2025-06-30T17:02:07.995Z
Last Seen

Product Information

Vendor TOTOLINK
Product T6
Version 4.1.5cu.748_B20211015

CVSS Information

Base Score 8.7 (HIGH)
Attack Vector CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A critical vulnerability in the TOTOLINK T6 router allows attackers to bypass authentication by exploiting the Form_Login function. This could grant unauthorized access to the device. The vulnerability is considered high severity due to its impact, though it requires local network access.
AI Severity High
Vendor TOTOLINK
Product T6
Affected Version 4.1.5cu.748_B20211015

Affected Products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Additional Information

CVE List
CWE List CWE-306, CWE-287
Bulletin Family

Description

A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the function Form_Login of the file /formLoginAuth.htm. The manipulation of the argument authCode/goURL leads to missing authentication. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.