Impact
The vulnerability is caused by incorrect access control in the getWiFiScheduleCfg function of the TOTOLINK T6 router firmware 4.1.5cu.748_B20211015, enabling an attacker to retrieve Wi‑Fi scheduling rules without authentication. This allows exposure of configuration data, which may aid in network reconnaissance or planning further attacks by revealing network usage patterns, but does not provide direct control or execution capabilities.
Affected Systems
The affected product is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendors or product lines are listed as impacted.
Risk and Exploitability
The vulnerability can be exploited by sending a crafted POST request to /cgi-bin/cstecgi.cgi from any entity that can reach the router, making it trivial to exploit with no credentials. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, suggesting it may not yet have widespread exploitation. Nonetheless, the ease of access and the potential value of the disclosed configuration data elevate the risk, warranting immediate mitigation.
OpenCVE Enrichment