Impact
Incorrect access control in the getMeshRoutingTable function allows an attacker to retrieve mesh routing information without authentication by sending a crafted POST request to /cgi-bin/cstecgi.cgi. The attacker can thus learn detailed network topology and routing entries, which may assist in further attacks, such as targeted traffic manipulation or reconnaissance.
Affected Systems
TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 are affected. No other affected models or firmware versions are listed.
Risk and Exploitability
The EPSS score of < 1% indicates a very low probability of exploitation, but the lack of KEV listing suggests no widespread active attacks at this time. The vulnerability remains in a publicly accessible endpoint and requires no credentials, indicating a remote network attack vector. The CVSS score of 7.5 classifies the flaw as high severity; the impact is unauthorized disclosure of mesh routing data, which could assist attackers in reconnaissance or targeted traffic manipulation.
OpenCVE Enrichment