CVE-2025-6916

HIGH

TOTOLINK T6 4.1.5cu.748_B20211015 - Missing Authentication via Form_Login

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-6916. PoCs published by c0nyy.

AI-analyzed exploit summary The repository contains a functional proof-of-concept for an authentication bypass vulnerability in TOTOLINK LR350 and T6 devices. The exploit manipulates the 'authCode' and 'goURL' parameters in a GET request to bypass login authentication.

Description

A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the function Form_Login of the file /formLoginAuth.htm. The manipulation of the argument authCode/goURL leads to missing authentication. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used.

Exploits (1)

nomisec WORKING POC
by c0nyy · poc
https://github.com/c0nyy/IoT_vuln

The repository contains a functional proof-of-concept for an authentication bypass vulnerability in TOTOLINK LR350 and T6 devices. The exploit manipulates the 'authCode' and 'goURL' parameters in a GET request to bypass login authentication.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: TOTOLINK LR350 (V9.3.5u.6369_B20220309) and T6 (V4.1.5cu.748_B20211015)
No auth needed
Prerequisites: Network access to the target device
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.314409
Permissions Required, Third Party Advisory, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.314409
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.605101
Product product
https://www.totolink.net/

Scores

CVSS v3 8.8
EPSS 0.0075
EPSS Percentile 49.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-287 CWE-306
Status published
Products (1)
totolink/t6_firmware v4.1.5cu.748_b20211015
Published Jun 30, 2025
Tracked Since Feb 18, 2026