Impact
The vulnerability resides in the getUPnPCfg function of TOTOLINK T6 routers, where an unauthenticated attacker can trigger a crafted POST request to /cgi-bin/cstecgi.cgi and retrieve the UPnP enablement status and parsed port‑mapping information. This flaw is an example of incorrect access control – the router exposes sensitive configuration details without requiring authentication. Consequently, an attacker gains confidential network information that could aid in planning further intrusions, such as discovering exposed ports or mapping internal services.
Affected Systems
Affected products are TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. The vulnerability is present in the firmware, and no other firmware versions are presently documented. Administrators should identify if their devices run the vulnerable firmware or a later revision that contains the fix.
Risk and Exploitability
Risk appears moderate because the flaw only provides information disclosure. However, the attack vector is straightforward: a victimless POST request to the exposed CGI endpoint over the local network or, if the router is accessible from the internet, remotely. With the EPSS score unavailable and the vulnerability not listed in the KEV catalog, the likelihood of exploitation is uncertain but should not be ignored. The CVSS score is not provided, yet the misuse of UPnP configuration data can be leveraged by attackers for reconnaissance or to identify exploitable services.
OpenCVE Enrichment