Impact
This vulnerability resides in the getWiFiApcliScan function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015 and permits an unauthenticated attacker to trigger a wireless scan and retrieve the list of connected AP‑client devices by sending a crafted POST request to /cgi-bin/cstecgi.cgi. The flaw is an access‑control weakness that leaks potentially sensitive information about network clients without requiring any credentials.
Affected Systems
The affected product is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendors or products are listed as impacted.
Risk and Exploitability
The exploit is straightforward: an attacker who can reach the router’s HTTP interface can send the malicious POST request from a compromised or malicious host on the local network, triggering the wireless scan and exfiltrating the AP‑client list. The CVSS score is 9.8, and the lack of authentication requirement and the unsolicited data disclosure make the risk significant. EPSS score is <1% and the CVE is not listed in the CISA KEV catalog, but the nature of the flaw suggests that an exploit, once available, could be widely used. The primary attack vector is network‑based, requiring access to the router’s management interface.
OpenCVE Enrichment