Impact
An access‑control flaw in the getWiFiGuestCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015 allows an attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi and retrieve guest Wi‑Fi configuration data. The vulnerability represents a CWE‑284 improper access‑control flaw. Inferred from the disclosed information, the attacker could obtain SSID and password, potentially enabling unauthorized access to the guest network.
Affected Systems
TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 are affected. No other versions or product lines are mentioned in the provided data.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score of <1% suggests a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because authentication is not required, any entity with network connectivity to the router could potentially send the crafted POST request. This is inferred as the likely attack vector is a local network attacker with access to the router’s management interface.
OpenCVE Enrichment