Impact
The vulnerability is an incorrect access control in the getLanCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. A crafted POST request to /cgi-bin/cstecgi.cgi allows any unauthenticated user to retrieve LAN addressing and DHCP configuration data, exposing sensitive network configuration.
Affected Systems
TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015 are affected. No other product versions are listed in the CNA data.
Risk and Exploitability
An attacker with network access to the device can exploit this flaw by sending a simple HTTP POST request, circumventing authentication entirely. While no CVSS or EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, the information disclosure can aid attackers in mapping the network, potentially escalating to further attacks.
OpenCVE Enrichment