Impact
An incorrect access control in the getWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows an unauthenticated attacker to retrieve mesh configuration and runtime state data by sending a crafted POST request to /cgi-bin/cstecgi.cgi. This flaw permits disclosure of sensitive network configuration and operational details without requiring valid credentials.
Affected Systems
TOTOLINK T6 devices running firmware version 4.1.5cu.748_B20211015 are affected. No other vendors or products are listed.
Risk and Exploitability
The vulnerability can be exploited remotely over the local network by directing a POST request to the specified CGI endpoint; authentication is not required. The CVSS score of 7.5 indicates high severity, while the EPSS score of < 1% suggests a low probability of active exploitation as of now. The issue is not listed in CISA KEV, implying limited known exploitation. Nonetheless, secrets disclosed could compromise network confidentiality and operational security.
OpenCVE Enrichment