Impact
The vulnerability in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 arises from incorrect access control in the getParentalRules function. By sending a crafted POST request to /cgi-bin/cstecgi.cgi, an attacker can retrieve the device’s parental‑control rules without authentication. This exposure could reveal sensitive routing policies or user activity, representing a breach of confidentiality and potentially allowing adversaries to bypass or manipulate traffic controls.
Affected Systems
TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No other versions or products are currently listed as affected.
Risk and Exploitability
The flaw is exploitable over the network and requires no credentials; a simple POST request suffices. Because the EPSS score is < 1% and the issue is not listed in CISA’s KEV catalog, the current likelihood of exploitation is low, but the absence of authentication makes the attack path straightforward. With a CVSS score of 9.1, the vulnerability is rated high severity, underscoring the need for prompt action.
OpenCVE Enrichment