Impact
The vulnerability is an incorrect access control in the getUrlFilterRules function of TOTOLINK T6 firmware. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and retrieve DMZ configuration information. This exposure of network configuration can assist attackers in planning further compromises, but the description does not state that any code is executed or direct control is obtained.
Affected Systems
TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 are affected. No other product versions or vendors are listed in the data.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity impact, while the EPSS score of <1% suggests that exploitation is unlikely currently. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs network access and can send a crafted HTTP POST request to /cgi-bin/cstecgi.cgi without authentication or privilege escalation. The exposed DMZ configuration can aid further attacks but does not grant code execution. The risk can be considered moderate but potentially high if the router is exposed to untrusted networks.
OpenCVE Enrichment