Impact
This vulnerability allows an unauthenticated attacker to retrieve Wi‑Fi Access Control List (ACL) rules from a TOTOLINK T6 device. The flaw resides in the getWiFiAclRules function, which incorrectly permits any user with network access to send a crafted POST request to /cgi-bin/cstecgi.cgi and receive the ACL contents. The primary impact is the compromise of confidentiality for the network configuration, potentially revealing which devices are whitelisted or blocked. The weakness is characteristic of an access control failure, enabling data disclosure without authentication. The CVE description specifies that no credentials are required for exploitation; the attacker only needs the ability to reach the device's HTTP endpoint.
Affected Systems
Affected devices are TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No other vendors or product lines are mentioned. Users of this specific firmware revision should verify their device model and version against the description to determine exposure.
Risk and Exploitability
Because the flaw is remote and requires no prior authentication, an attacker can exploit it from any location that can reach the router's web interface. The CVSS score is not provided, and the EPSS score is absent, so the quantitative exploitation likelihood is unknown. The vulnerability is not listed in CISA KEV, suggesting no known in‑field exploitation yet. Nevertheless, the attacker can obtain sensitive network configuration details, which may be leveraged in a broader attack strategy. Given the unrestricted access and lack of mitigations by default, the vulnerability is considered high risk for any exposed device.
OpenCVE Enrichment