Impact
The vulnerability involves an incorrect access control check in the getInitCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker who sends a crafted POST request to /cgi-bin/cstecgi.cgi can retrieve sensitive configuration information without needing valid credentials.
Affected Systems
The affected device is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendors or product versions are listed in the vulnerability report, so remediation efforts should focus on this specific hardware/firmware combination.
Risk and Exploitability
Since the CVSS score is 7.5 and the EPSS score is below 1%, the vulnerability is considered high severity with a low probability of exploitation, and it is not listed in the CISA KEV catalog. The attack vector is network based, relying on an unauthenticated POST request to a publicly reachable CGI endpoint. The flaw allows attackers to retrieve sensitive configuration information without valid credentials.
OpenCVE Enrichment