Impact
The vulnerability is an incorrect access control in the getWiFiBasicCfg function of the TOTOLINK T6 router. An unauthenticated attacker can send a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint and retrieve the device’s core wireless settings, including SSIDs and Wi‑Fi keys. This results in a confidentiality breach that exposes network credentials and allows an attacker to connect to the Wi‑Fi network without authorization.
Affected Systems
The affected device is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. The vulnerability is present in the getWiFiBasicCfg function that is accessed via the router’s web interface.
Risk and Exploitability
There is no EPSS or CVSS score available, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the lack of authentication and the need only to send a POST request to a documented CGI endpoint make exploitation straightforward for an attacker with network access. If the router is exposed to the local network or, less commonly, to the public internet, an attacker could obtain Wi‑Fi credentials with minimal effort. The risk to confidentiality is high, while limited information indicates that impact on integrity and availability is minimal.
OpenCVE Enrichment