Impact
The vulnerability lies in the getDdnsCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015, where access control checks are missing. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and retrieve DDNS configuration details—including domain, username, and password. This grants the attacker the ability to hijack DDNS services, manipulate name resolution, and potentially use the compromised credentials to gain further network access. The weakness aligns with improper access control (CWE‑284).
Affected Systems
The affected product is the TOTOLINK T6 wireless router running firmware version 4.1.5cu.748_B20211015. No other firmware releases are listed as impacted by this issue. The vulnerability could affect any installation of this device that retains the default settings for DDNS configuration access.
Risk and Exploitability
The flaw allows unauthenticated requests from any host that can reach the router, making exploitation both straightforward and low effort. No CVSS or EPSS score is available, and the vulnerability is not catalogued in CISA KEV, suggesting that it has not yet been widely exploited. However, if the router is reachable from an untrusted network or the Internet, the risk of exploitation could be higher, as the attacker would obtain sensitive credentials without needing to compromise local credentials.
OpenCVE Enrichment