Impact
The flaw is an incorrect access control on the getMacFilterRules function in the TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can craft a POST request to /cgi-bin/cstecgi.cgi and retrieve the router's MAC filter list. This exposes confidential configuration data—including allowed and blocked MAC addresses—without requiring any login credentials. The weakness is a classic improper authorization flaw (CWE‑284).
Affected Systems
The issue impacts TOTOLINK T6 routers that are running firmware version 4.1.5cu.748_B20211015. No other TOTOLINK product lines or vendor families are listed as affected in the current disclosure.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity for an information‑disclosure vulnerability, while the EPSS score of less than 1% suggests a low likelihood of public exploitation. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote HTTP POST request from any network able to reach the router's web interface. The vulnerability allows a read of the MAC filter configuration only; it does not provide authentication bypass for other privileged operations or remote code execution.
OpenCVE Enrichment