Impact
Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 gives attackers an unauthenticated window to probe the /cgi-bin/cstecgi.cgi endpoint. Because the weakness maps to CWE‑284 (Improper Access Control), the attacker can obtain cloud firmware check status information that may include device identifiers, firmware revision, and other operational details. This leakage compromises confidentiality but does not grant execution privileges or further control over the device.
Affected Systems
TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 are affected. No other vendors or products appear to be impacted according to the available data.
Risk and Exploitability
The EPSS score is missing and the vulnerability is not listed in CISA KEV. With no CVSS score presented, the formal severity remains unspecified. Nonetheless the remote, unauthenticated network‑based attack path through an HTTP POST request indicates a potentially high risk of information disclosure in environments where the router is exposed to untrusted networks. Monitoring and timely patching are recommended to mitigate the threat.
OpenCVE Enrichment