Impact
The vulnerability lies in an incorrect access control check in the getWiFiIpMacTable function of the TOTOLINK T6 router firmware. An unauthenticated attacker can trigger a crafted POST request to /cgi-bin/cstecgi.cgi to retrieve the MAC‑to‑IP mapping table of Wi‑Fi clients. This disclosure reveals the network topology and client identities, which can be leveraged for targeted attacks or network reconnaissance.
Affected Systems
TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 are affected. No other vendors, products, or versions are listed.
Risk and Exploitability
The firmware contains no authentication for the vulnerable CGI endpoint, so any host with network reach to the device can exploit the flaw. No CVSS score or EPSS data are provided, and the vulnerability is not listed in the CISA KEV catalog, making the exploitation probability difficult to quantify. However, the straightforward nature of the attack path and the sensitive information exposed suggest a high potential impact for organizations that allow external or untrusted hosts to reach the internal routing device.
OpenCVE Enrichment