Impact
Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 gives attackers an unauthenticated window to probe the /cgi-bin/cstecgi.cgi endpoint. Because the weakness maps to CWE‑284 (Improper Access Control), the attacker can obtain cloud firmware check status information that may include device identifiers, firmware revision, and other operational details. This leakage compromises confidentiality but does not grant execution privileges or further control over the device.
Affected Systems
TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 are affected. No other vendors or products appear to be impacted according to the available data.
Risk and Exploitability
The EPSS is less than 1%, indicating a low but non‑zero exploitation probability. The CVSS score of 7.5 classifies the vulnerability as High severity. The weakness is listed under CWE‑284 and is not featured in the CISA KEV catalog. Attackers can exploit the open /cgi‑bin/cstecgi.cgi endpoint via an unauthenticated POST request, revealing cloud firmware status information that could expose device identifiers, firmware revisions, or other operational data. Although it does not allow code execution or direct device control, the confidentiality breach may aid further reconnaissance or targeted attacks. Monitoring and timely patching are recommended to mitigate the threat.
OpenCVE Enrichment