Impact
The vulnerability resides in a function that retrieves guest Wi-Fi configuration without enforcing proper authorization. An attacker who can send a crafted POST request to the CGI endpoint is able to pull a simplified guest network configuration, which includes the password. This enables a non‑authenticated user to join the guest network and potentially eavesdrop on traffic, perform man‑in‑the‑middle attacks, or compromise shared network resources.
Affected Systems
The flaw is present in the TOTOLINK T6 router model running firmware version 4.1.5cu.748_B20211015. No other affected products or versions are listed.
Risk and Exploitability
Because the vulnerability is accessible from outside the local network and does not require authentication, the potential for exploitation is high. The CVSS score is not reported, and there is no EPSS data or KEV listing available. Nonetheless, the impact of leaking guest credentials is significant for network security, especially in environments where guest access is widely used.
OpenCVE Enrichment