Impact
The vulnerability resides in the getRoamingCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015, where incorrect access control allows an unauthenticated attacker to query a roaming enablement flag via a crafted POST request to /cgi-bin/cstecgi.cgi. This flaw can disclose configuration information and potentially facilitate further manipulation of network settings. The weakness corresponds to improper access control (CWE-284).
Affected Systems
The affected device is a TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendors or products are listed.
Risk and Exploitability
The flaw can be exploited remotely over HTTP without authentication, making it straightforward for adversaries with network visibility. This is inferred from the description that unauthenticated POST requests to /cgi-bin/cstecgi.cgi are permitted. No CVSS or EPSS metrics are available, and the vulnerability is not in the CISA KEV catalog. While the immediate impact is the exposure of a single configuration flag, it could serve as an initial foothold for attackers to seek higher privileges; this potential is inferred because the vulnerability could be a stepping stone if further configuration changes are possible. The attack path requires only a crafted POST request, indicating low exploitation complexity; this is inferred from the stated requirement of a single crafted request.
OpenCVE Enrichment