Impact
The flaw resides in the getRemoteCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015, allowing an attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi without authentication and retrieve the status of remote‑management enablement and associated port information. The vulnerability is an improper authorization weakness that leads to the disclosure of configuration details that could aid further attacks, such as lateral movement or exploitation of exposed management interfaces. No execution is possible from the request itself, but the exposed data can be leveraged to plan subsequent attacks.
Affected Systems
All devices running TOTOLINK T6 version 4.1.5cu.748_B20211015 are impacted. The vendor has not supplied a separate patch list, so any installation of the mentioned firmware should be considered vulnerable.
Risk and Exploitability
Because the flaw permits unauthenticated data disclosure, it is of high potential impact for a target that relies on confidentiality of management settings. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, but the absence of a known patch and the ability to obtain sensitive configuration details suggest a notable risk. The vulnerability is not listed in the CISA KEV catalog, yet administrators should not assume it is safe to ignore.
OpenCVE Enrichment