Impact
TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015 have a weak access control mechanism in the getWanInfo function. This flaw allows an attacker who has not authenticated to obtain the device’s WAN information by sending a specially crafted POST request to /cgi-bin/cstecgi.cgi. The disclosed data may reveal public IP addresses, gateway details, and DNS settings that can facilitate further reconnaissance or targeted attacks against the network.
Affected Systems
The exposure applies to the TOTOLINK T6 router family, specifically firmware version 4.1.5cu.748_B20211015. No other firmware or hardware versions are noted in the advisory.
Risk and Exploitability
The vulnerability permits unauthenticated data extraction from the device; the likely attack vector is remote via the web interface, though specific network prerequisites are not detailed in the description. EPSS is currently not reported, and the attack is not listed in the CISA KEV catalog, but the lack of authentication still represents a significant information disclosure risk. Due to the absence of a CVSS score, the severity assessment must rely on the factual impact: any attacker able to reach the device can gain WAN configuration details.
OpenCVE Enrichment