Impact
The getDeviceInfo function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an access‑control flaw. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and receive the device's identification data, such as serial number, firmware version and network identifiers. This enables information disclosure and can be employed as a foothold for subsequent targeted attacks on the internal network. The flaw is an example of improper access control (CWE‑284).
Affected Systems
Affected systems are ONLY the TOTOLINK T6 router running the firmware version 4.1.5cu.748_B20211015 or earlier builds that have not applied the patch. No other vendors are reported in the CNA data. The vulnerability originates within the device's internal CGI interface and does not rely on user interaction beyond sending the HTTP request.
Risk and Exploitability
No CVSS score or EPSS data are currently available, so the quantitative severity is unknown. The vulnerability is remotely exploitable over the local network and can be triggered by any host that can reach the router. Because it allows the disclosure of sensitive device metadata, the risk is moderate to high for individuals or organizations that require strong device anonymity or rely on default firewall settings to block unauthenticated requests. The CVE is not listed in the CISA KEV catalog, but mitigation should still be applied promptly to prevent opportunistic reconnaissance by adversaries.
OpenCVE Enrichment