Impact
The getWiFiEasyCfg function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an improper access control flaw that allows attackers without authentication to send a crafted POST request to /cgi-bin/cstecgi.cgi and retrieve the SSID and Wi‑Fi password. This disclosure enables attackers to join the wireless network and potentially perform further attacks. The weakness aligns with CWE-284, improper access control, and CWE-200, exposure of sensitive information to an unauthorized actor.
Affected Systems
TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 are affected. No other versions are listed in the advisory.
Risk and Exploitability
The vulnerability is accessible over the router’s web interface without requiring credentials, so an attacker simply needs network reachability to the device. Although no EPSS or CVSS values are available, the lack of authentication and the value of the leaked data suggest a high exploitation likelihood. The flaw is not included in the CISA KEV catalog.
OpenCVE Enrichment