CVE-2025-6916
HIGHTOTOLINK T6 4.1.5cu.748_B20211015 - Missing Authentication via Form_Login
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-6916. PoCs published by c0nyy.
AI-analyzed exploit summary The repository contains a functional proof-of-concept for an authentication bypass vulnerability in TOTOLINK LR350 and T6 devices. The exploit manipulates the 'authCode' and 'goURL' parameters in a GET request to bypass login authentication.
Description
A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the function Form_Login of the file /formLoginAuth.htm. The manipulation of the argument authCode/goURL leads to missing authentication. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used.
Exploits (1)
The repository contains a functional proof-of-concept for an authentication bypass vulnerability in TOTOLINK LR350 and T6 devices. The exploit manipulates the 'authCode' and 'goURL' parameters in a GET request to bypass login authentication.
References (5)
Scores
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H