Impact
The vulnerability is an incorrect access control in the getMacFilterRules function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. Unauthenticated attackers can craft a POST request to /cgi-bin/cstecgi.cgi and retrieve the router's MAC filter rules. This exposes confidential configuration data without requiring any authentication, allowing an attacker to see which MAC addresses are allowed or blocked on the device.
Affected Systems
The issue affects TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. No other vendors or product lines are listed as affected by the current disclosure.
Risk and Exploitability
The attack requires only a crafted HTTP POST request, meaning the vulnerability can be exploited remotely from any network that can reach the router's web interface. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited publicly known exploitation. Nevertheless, the ability to obtain MAC filter rules can aid future targeted attacks and should be mitigated promptly.
OpenCVE Enrichment