Impact
The vulnerability resides in the getVpnPassCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015 and allows unauthenticated access to sensitive configuration data. Because of incorrect access control, a crafted POST request to /cgi-bin/cstecgi.cgi returns VPN pass-through and WAN ping filter settings without requiring authentication. The information exposed could aid a malicious actor in understanding the network’s bypass behavior, potentially facilitating further compromise or misconfiguration. The weakness is an improper access control flaw as identified by CWE-284.
Affected Systems
TOTOLINK T6 devices running firmware version 4.1.5cu.748_B20211015 are affected. No other versions or product variants are listed in the available data.
Risk and Exploitability
The CVSS score is 4.3, indicating moderate severity, and the EPSS score is <1%, suggesting low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack vector is clear: an external unauthenticated attacker must reach the device’s HTTP interface. The exploit requires only a crafted POST request, meaning that any device reachable from the Internet or an internal network can be targeted if the vulnerable endpoint is exposed. In the absence of a vendor-supplied patch, the risk is mitigated by restricting or blocking access to the /cgi-bin/cstecgi.cgi endpoint or by isolating the device in a separate network segment.
OpenCVE Enrichment