Impact
The getWanCfg function in TOTOLINK T6 firmware incorrectly accepts unauthenticated POST requests to return WAN configuration data. An attacker that can reach the router via the web interface can therefore obtain sensitive network settings, potentially compromising the overall security of the local network. The weakness falls into Improper Authorization (CWE-284).
Affected Systems
The flaw is present in TOTOLINK T6 routers running firmware release 4.1.5cu.748_B20211015. Any deployment of this exact firmware revision is vulnerable.
Risk and Exploitability
Exploitation requires only network connectivity to the router and no credentials; an attacker can send a crafted POST to /cgi-bin/cstecgi.cgi to retrieve the configuration. The CVSS score of 9.1 classifies this vulnerability as high severity, and the EPSS score of <1% indicates a low probability of exploitation in the wild. Although the issue is not listed in the CISA KEV catalog, the ability to read WAN configuration can aid further attacks and is therefore considered a moderate to high risk depending on the environment. The entrance path is straightforward and the exploitation skill level is low.
OpenCVE Enrichment