Impact
TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 contains an improper access control flaw in the getOnlineClient function. The flaw allows an attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi and receive online client information without authentication. This represents a vulnerability for which the exploited weakness is classified as CWE-284: Improper Access Control, providing unauthorized disclosure of data to external parties.
Affected Systems
The affected product is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015.
Risk and Exploitability
The vulnerability permits unauthenticated attackers to obtain potentially sensitive client information over the network. The EPSS score is less than 1%, indicating a low probability of exploitation. Based on the available information, no public exploit or exploit code has been reported. The CVSS score of 7.5 indicates a medium to high severity, confirming a significant confidentiality risk. There is no indication that this vulnerability is listed in the CISA KEV catalog.
OpenCVE Enrichment