Impact
The getDeviceInfo function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an improper access‑control bug (CWE‑284). An unauthenticated attacker can send a specially crafted POST request to /cgi-bin/cstecgi.cgi and receive device identification data such as the serial number, firmware version, or network identifiers. This grants an attacker the ability to learn the router's internal details without authenticating, which constitutes information disclosure.
Affected Systems
Only the TOTOLINK T6 router running the firmware version 4.1.5cu.748_B20211015 is affected. Earlier firmware releases that have not applied a subsequent patch may also be vulnerable, but the issue is documented only for this specific build. No other vendors or products are listed as affected in the CNA data.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3, indicating a low to moderate severity in the CVSS v3 scale. An EPSS score of less than 1% suggests a very low probability of exploitation at present. The flaw is remotely exploitable over the local network by any host that can reach the router's HTTP interface, and it is not listed in the CISA KEV catalog, so it is not a known, actively exploited vulnerability.
OpenCVE Enrichment