Impact
An unauthorized attacker can trigger the getDmzCfg function in the router’s cgi-bin endpoint by sending a crafted POST request to /cgi-bin/cstecgi.cgi. Because the function lacks proper authentication checks, the attacker receives the DMZ configuration data, revealing network layout and potential target details.
Affected Systems
The flaw exists only in the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendors or products are reported as affected. The vulnerability is confined to the router’s web management interface, which may be exposed to the local network or the Internet.
Risk and Exploitability
The CVSS score of 7.5 is reported, and the EPSS score is < 1%. The flaw is not in the CISA KEV catalog. Attackers would need network access to the router’s web interface; thus the threat vector is local or remote if the device is Internet‑exposed. While exploitation requires crafting a POST request, the lack of publicly available exploit code indicates moderate risk, but the potential for revealing critical network information mandates prompt action.
OpenCVE Enrichment