Impact
A flaw in the getWiFiAdvancedCfg function of the TOTOLINK T6 router firmware 4.1.5cu.748_B20211015 allows an attacker without authentication to retrieve advanced wireless settings by sending a crafted POST request to /cgi-bin/cstecgi.cgi. The vulnerability is an incorrect access control that exposes sensitive configuration information that could aid in planning further attacks or detailed network reconnaissance.
Affected Systems
The vulnerability affects TOTOLINK Home Router T6 units running firmware version 4.1.5cu.748_B20211015. No other device models or firmware revisions were identified as impacted in the available data.
Risk and Exploitability
The exploitation path requires network access to the router and does not rely on user interaction beyond sending the crafted POST request. Because no EPSS or CVSS score is provided, the exact exploitation probability is uncertain, but the flaw allows unauthenticated information disclosure, which is typically considered high risk. The vulnerability is not listed in the CISA KEV catalog and no public exploit has been documented at this time.
OpenCVE Enrichment