Impact
Incorrect access control in the getMeshRoutingTable function allows an attacker to retrieve mesh routing information without authentication by sending a crafted POST request to /cgi-bin/cstecgi.cgi. The attacker can thus learn detailed network topology and routing entries, which may assist in further attacks, such as targeted traffic manipulation or reconnaissance.
Affected Systems
TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 are affected. No other affected models or firmware versions are listed.
Risk and Exploitability
No EPSS data or KEV listing is available, so the exploitation likelihood is unclear. The flaw exists in a publicly accessible endpoint and requires no credentials; therefore the attack vector is remote over the network. The impact is confidential information disclosure which could support additional attacks. Without a CVSS score, the overall risk is considered high due to the unauthenticated nature of the vulnerability.
OpenCVE Enrichment