Impact
An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi on a TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015 to obtain the device’s port‑forwarding configuration. Because the getPortForwardRules function does not enforce proper authentication, the attacker obtains sensitive configuration details that could reveal open ports, services, and potential entry points for further attacks. This represents a confidentiality breach that could facilitate additional exploitation of the router or connected network.
Affected Systems
Integrating vendor TOTOLINK’s T6 line of routers with firmware 4.1.5cu.748_B20211015 is impacted. This includes all devices shipped or updated to this specific firmware build. No other TOTOLINK models or firmware versions are listed as affected.
Risk and Exploitability
The vulnerability can be executed without authentication over the router’s web interface, which is typically reachable from connected networks and potentially the Internet if port forwarding is enabled. While there is no publicly available EPSS score, the absence of authentication requirements and the sensitive data disclosed suggest a moderate to high risk of exploitation. The vulnerability is not listed in the CISA KEV catalog, but responsible disclosure indicates it is actively investigated by vendor and security communities.
OpenCVE Enrichment