Impact
The getWanCfg function in TOTOLINK T6 firmware incorrectly accepts unauthenticated POST requests to return WAN configuration data. An attacker that can reach the router via the web interface can therefore obtain sensitive network settings, potentially compromising the overall security of the local network. The weakness falls into Improper Authorization (CWE-284) and Information Exposure (CWE-200).
Affected Systems
The flaw is present in TOTOLINK T6 routers running firmware release 4.1.5cu.748_B20211015. Any deployment of this exact firmware revision is vulnerable.
Risk and Exploitability
Exploitation requires only network connectivity to the router and no credentials; an attacker can send a crafted POST to /cgi-bin/cstecgi.cgi to retrieve the configuration. EPSS data is not available and the issue is not listed in the CISA KEV catalog, yet the ability to read WAN configuration can aid further attacks and is therefore considered a moderate to high risk depending on the environment. The entrance path is straightforward and the exploitation skill level is low.
OpenCVE Enrichment