In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/204/ids/36.html
https://gist.github.com/lin-3-start/e42344d5caea881e5429fdd40fad1fd8