Impact
The vulnerability exists in the getNtpCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015, where access control is incorrectly implemented. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and retrieve the device’s NTP configuration as well as the current time. This enables exposure of sensitive configuration data; while it does not directly lead to remote code execution, the leaked information could help in further attacks or facilitate more sophisticated reconnaissance. The flaw is a classic example of missing authentication or authorization checks in a web‑based interface.
Affected Systems
The flaw affects TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No other vendors or products are known to be impacted.
Risk and Exploitability
The flaw is exploitable remotely without authentication over the network. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it may be relatively low frequency, but the enterprise impact of exposing NTP configuration is non‑trivial. Given the remote nature of the attack, an attacker could enumerate multiple devices if the same firmware version is in use. The risk level is moderate, with potential for escalation if additional information aids future exploitation.
OpenCVE Enrichment