Impact
The flaw exists in the getScheduleCfg routine of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An attacker can trigger the routine by sending a crafted POST request to /cgi-bin/cstecgi.cgi, which returns schedule or scheduled‑reboot configuration details. Because authentication or access checks are missing, the device discloses sensitive configuration information, violating confidentiality. This is an information‑disclosure weakness classified as CWE‑284.
Affected Systems
The affected product is the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. No other firmware releases were identified as vulnerable. Only devices with this exact release are impacted.
Risk and Exploitability
The CVSS score is 4.3, an intermediate level that reflects potential disclosure without privilege requirements. The EPSS score is below 1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV database. The likely attack vector is a network path that can reach the router’s web interface, such as a local LAN or an exposed Internet gateway. An attacker only needs to send the crafted HTTP POST to /cgi-bin/cstecgi.cgi, with no additional exploits or user interaction required, making the flaw straightforward to use in environments where the router is reachable from untrusted networks.
OpenCVE Enrichment