Impact
An unauthenticated attacker can retrieve syslog configuration data by sending a crafted POST request to /cgi-bin/cstecgi.cgi on TOTOLINK T6 devices running firmware 4.1.5cu.748_B20211015. The vulnerability is a failure of access control that allows exposure of configuration values that may include logging enabled status, destination hosts, and potentially other diagnostic information. Such disclosure can aid an attacker in mapping network topology, identifying potentially exploitable services, or preparing targeted attacks, thereby impacting confidentiality and serve as groundwork for more severe exploits.
Affected Systems
Hardware vendor TOTOLINK, product T6, firmware 4.1.5cu.748_B20211015.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploitation. The CVSS score of 9.1 classifies the vulnerability as Critical, highlighting the substantial risk of information disclosure should unauthenticated attackers obtain syslog configuration. The attack requires unauthenticated HTTP access, likely limited to an internal network or Internet‑exposed device. Despite the low EPSS, the high severity recommends immediate remediation.
OpenCVE Enrichment