Impact
The vulnerability involves an incorrect access control check in the getInitCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker who sends a crafted POST request to /cgi-bin/cstecgi.cgi can retrieve sensitive configuration information without needing valid credentials.
Affected Systems
The affected device is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendors or product versions are listed in the vulnerability report, so remediation efforts should focus on this specific hardware/firmware combination.
Risk and Exploitability
Because no exploit probability data is available and the issue is not listed in the CISA KEV catalog, the exact risk level cannot be quantified, but the described unauthorized access to configuration data is a severe security concern. The attack vector is network based, relying on an unauthenticated POST request to a publicly reachable CGI endpoint.
OpenCVE Enrichment