Impact
The getWiFiEasyCfg function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an improper access control flaw that allows attackers without authentication to send a crafted POST request to /cgi-bin/cstecgi.cgi and retrieve SSID and Wi‑Fi password. The disclosure permits attackers to obtain sensitive network credentials. The weakness aligns with CWE-284, improper access control.
Affected Systems
TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 are affected.
Risk and Exploitability
Unauthenticated attackers can send a crafted POST request to /cgi-bin/cstecgi.cgi to retrieve SSID and Wi‑Fi password. The vulnerability's CVSS score of 7.5 reflects its severity, and the EPSS score of < 1% indicates low exploitation probability. The flaw is not listed in the CISA KEV catalog.
OpenCVE Enrichment