Impact
The total vulnerability arises from incorrect access control in the getStorageCfg function of the TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An attacker who can reach the device can send a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint and receive the current storage feature state. This disclosure does not provide direct system compromise, but it exposes operational configuration that might aid further attacks. The weakness is a classic instance of CWE-284, improper access control, where a function does not enforce proper authentication before returning sensitive state data.
Affected Systems
The only affected product documented is the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. No other vendors or product lines are listed as impacted in the available data.
Risk and Exploitability
Because the flaw is triggered by an unauthenticated POST request to the publicly reachable /cgi-bin/cstecgi.cgi endpoint, the attack vector is network-based and does not require authentication or privileged credentials. The CVSS score is 4.3, the EPSS score is less than 1%, and the vulnerability is not reported in the CISA KEV catalog. The impact is the disclosure of the current storage feature state. While the disclosure does not directly facilitate system compromise, it could provide an attacker with configuration details that might be useful for planning further attacks, but no evidence indicates that it has been widely exploited in the wild.
OpenCVE Enrichment