Impact
The vulnerability resides in the getRoamingCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015, where incorrect access control allows an unauthenticated attacker to query a roaming enablement flag via a crafted POST request to /cgi-bin/cstecgi.cgi. This flaw can disclose configuration information and potentially facilitate further manipulation of network settings. The weakness corresponds to improper access control (CWE-284).
Affected Systems
The affected device is a TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendors or products are listed.
Risk and Exploitability
The flaw can be exploited remotely over HTTP without authentication, making it straightforward for adversaries with network visibility. The CVSS score of 9.1 classifies the vulnerability as critical, while the EPSS score of <1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attacker can obtain the roaming enablement flag by crafting a POST request to /cgi-bin/cstecgi.cgi, which requires no prior authentication or special privileges. While the immediate impact is the exposure of a single configuration flag, this disclosure could serve as an initial foothold for attackers to seek higher privileges if further configuration changes are possible. The attack path requires only a crafted POST request, indicating low exploitation complexity.
OpenCVE Enrichment