Impact
The vulnerability resides in an improper access control within the getTelnetCfg function, enabling unauthenticated attackers to query whether Telnet is enabled by sending a crafted POST request to /cgi-bin/cstecgi.cgi. The disclosed data is purely the Telnet enablement status, which provides an attacker insight into the router's configuration and potential attack surface, aiding reconnaissance and future exploitation planning.
Affected Systems
TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 are affected by this weakness. No other vendors or versions are listed in the available data.
Risk and Exploitability
A formal CVSS score is not provided, and the EPSS score is unavailable, so the quantitative severity cannot be determined. The vulnerability can be exploited over an unauthenticated network connection by sending a simple crafted POST request, and the KEV catalog does not list it as currently exploited. Because the attack requires no credentials and only exposes service status, the immediate risk is moderate; however, if Telnet is enabled, the disclosed information can facilitate further attacks. The availability of an unauthenticated access point remains a noteworthy weakness.
OpenCVE Enrichment