Impact
A flaw in the getTracerouteCfg function permits an unauthenticated requester to retrieve traceroute logs without proper authorization. The vulnerability is due to missing access control checks on the /cgi-bin/cstecgi.cgi endpoint, which, when a specially crafted POST request is sent, returns diagnostic data that may contain network topology and device information. The impact is the disclosure of sensitive network configuration data, potentially aiding attackers in mapping the local environment.
Affected Systems
The issue affects TOTOLINK routers, specifically model T6 running firmware version 4.1.5cu.748_B20211015. No broader version range is indicated; the vulnerability was identified in this particular build.
Risk and Exploitability
Because the flaw allows unauthenticated exploitation, any host with network reachability to the target router could trigger the disclosure by sending a crafted POST request. The EPSS score is not available and the CVE is not listed in the CISA KEV catalog, so the likelihood of widespread exploitation is uncertain. Nonetheless, the lack of authentication represents a serious security gap that could be leveraged by attackers with knowledge of the router's IP address.
OpenCVE Enrichment