Impact
The vulnerability resides in the getWanIeCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and obtain LAN addressing and DHCP configuration information. The flaw is an incorrect access control that allows disclosure of sensitive network configuration, compromising confidentiality of the local network. The likely attack vector is via the router’s HTTP interface, enabling remote or local attackers to retrieve configuration data without authentication.
Affected Systems
The affected device is a TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. No other affected versions are listed.
Risk and Exploitability
The CVSS score is not available, and the EPSS score is not provided, meaning the global exploitation probability is unknown. The vulnerability is not listed in CISA KEV. However, because it allows unauthenticated disclosure of LAN configuration via a simple HTTP POST, the risk to confidentiality for any router owner is moderate. An attacker with network connectivity to the router can exploit the flaw by sending a crafted request to /cgi-bin/cstecgi.cgi, as no additional authentication or privilege is required.
OpenCVE Enrichment