Impact
The vulnerability originates from incorrect access control in the getSmartQosCfg function of the TOTOLINK T6 firmware. An attacker who can send a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint does not need authentication and can retrieve the Smart QoS configuration and rule set. This exposes detailed device settings that may reveal network topology, device roles, and potentially serve as a foothold for further attacks. The flaw thus permits unauthorized disclosure of sensitive configuration data and could aid attackers in planning more targeted intrusions.
Affected Systems
The affected system is the TOTOLINK T6 router model running firmware version 4.1.5cu.748_B20211015. No other vendor products or versions are listed in the CNA data.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploitation in the wild yet. However, the flaw is exploitable via a simple, unauthenticated HTTP request and could be leveraged by adversaries who can reach the device’s management interface. Without a patch, the risk remains significant for any network that exposes the router to untrusted traffic.
OpenCVE Enrichment