Impact
The vulnerability resides in the getCloudDownloadStatus function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. Because this function does not enforce any authentication check, an attacker can send a specially crafted POST request to /cgi-bin/cstecgi.cgi and retrieve the firmware download state of the device. This unauthorized disclosure allows an adversary to learn whether a firmware update is in progress, potentially revealing device lifecycle information that can aid in targeted attacks. The weakness corresponds to improper access control (CWE‑284).
Affected Systems
Affected systems include TOTOLINK T6 routers that are running firmware 4.1.5cu.748_B20211015. No other products or versions were identified in the advisory. Systems not running this exact build are not known to be affected.
Risk and Exploitability
The CVSS score is not provided and no EPSS value is available, so the exact severity and exploitation probability remain uncertain. However, because the flaw permits unauthenticated access and requires only a simple POST request, the attack vector is likely to be remote over the internet or a local network. As the vulnerability is not listed in the CISA KEV catalog, no publicly confirmed exploits are known yet, but the lack of authentication control makes it a low‑threat but potentially valuable target for reconnaissance.
OpenCVE Enrichment