Impact
An authentication bypass exists in the getDdnsStatus function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. By sending a specially crafted POST request to /cgi-bin/cstecgi.cgi, an unauthenticated attacker can retrieve the device's DDNS runtime status and its public IP address. This flaw allows disclosure of network configuration details that could be leveraged for further attacks, such as targeted reconnaissance or service exploitation.
Affected Systems
Total affected product: TOTOLINK T6 in firmware version 4.1.5cu.748_B20211015. No other versions or modules are listed as impacted in the available data.
Risk and Exploitability
The CVSS score of 7.5 classifies the vulnerability as High, while the EPSS score of < 1% indicates a very low probability of exploitation. The flaw is remotely exploitable without authentication and requires only a crafted HTTP POST to /cgi-bin/cstecgi.cgi, enabling attackers to retrieve the device's public IP and DDNS status. This disclosure can aid reconnaissance or pinpoint additional services, posing a moderate to high threat depending on the network context of the device. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment