Impact
An access‑control flaw exists in the getCrpcCfg function of TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker who can send a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint can retrieve the cloud remote‑control status and associated URL information. The vulnerability is a classic example of improper access control (CWE‑284); it does not provide remote code execution or denial‑of‑service capabilities, but it exposes configuration data that could facilitate further attacks such as remote control hijacking or reconnaissance. The disclosed information may be used to gain deeper insight into the router’s remote‑control capabilities and potentially tailor subsequent exploitation attempts.
Affected Systems
TOTOLINK T6 wireless routers running firmware version 4.1.5cu.748_B20211015 are affected. No other product variants or versions are listed in the advisory.
Risk and Exploitability
Because the flaw allows unauthenticated access, a threat actor with network proximity to the device can simply send a POST request without authentication. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so the community data on exploit prevalence is limited. Nonetheless, the fact that the vulnerability is not mitigated by authentication alone and leaks sensitive configuration data gives it a moderate to high risk posture, especially for environments where the router exposes interfaces to untrusted networks or hosts. A successful exploitation could provide the attacker a foothold to further compromise the device’s remote‑control features.
OpenCVE Enrichment