Impact
The vulnerability resides in the getWizardCfg function of TOTOLINK T6 firmware. An unauthenticated attacker can send a specially crafted POST request to /cgi-bin/cstecgi.cgi and retrieve the setup wizard and onboarding configuration data. This reveals sensitive configuration settings that an attacker could use to further compromise or clone the device. The weakness arises from improper access control that fails to verify authentication before exposing the data.
Affected Systems
The flaw affects TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015.
Risk and Exploitability
The CVSS score is not listed, the EPSS score is not available, and the vulnerability is not included in CISA’s KEV catalog. Based on the description, any entity with network visibility to the device can exploit the flaw by sending a POST request without authentication and obtain confidential configuration information. While no publicly available exploit or high exploitation probability has been reported, the exposure of configuration data may assist additional attacks and therefore presents a moderate risk.
OpenCVE Enrichment