Impact
The vulnerability resides in the getWiFiEasyGuestCfg function of the TOTOLINK T6 router. The function retrieves guest Wi‑Fi configuration data without enforcing any form of access control. An unauthenticated attacker who can send a crafted POST request to /cgi-bin/cstecgi.cgi can obtain a simplified guest network configuration, including the guest network password. Based on the description, it is inferred that the attacker could send this request remotely, potentially from outside the local network. This allows the attacker to join the guest network or perform network‑based attacks such as eavesdropping, man‑in‑the‑middle manipulation, or compromise of shared resources.
Affected Systems
The flaw is present in the TOTOLINK T6 router model running firmware version 4.1.5cu.748_B20211015. No other vendors, products, or firmware versions are identified as affected.
Risk and Exploitability
Based on the description, it is inferred that the vulnerability could be exploited remotely, although this is not explicitly confirmed. The CVSS score of 4.3 reflects low impact, the EPSS score indicates a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The exposure of guest credentials can lead to unauthorized network access and potential eavesdropping on traffic.
OpenCVE Enrichment