Impact
The vulnerability resides in the setDmzCfg function of the TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An incorrect access control check allows an attacker who can send a crafted POST request to /cgi-bin/cstecgi.cgi to expose an internal host without needing authentication. The primary impact is the disclosure of internal host information, which can be used for network reconnaissance or as a foothold for further attacks. The weakness maps to the improper access control category identified as CWE‑284.
Affected Systems
The affected product is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No additional affected versions are listed in the CVE metadata, and the vendor is identified only as TOTOLINK. The flaw is located in the setDmzCfg function reachable via the /cgi-bin/cstecgi.cgi path.
Risk and Exploitability
The CVE has a CVSS score of 9.8, indicating critical severity, and an EPSS score of < 1%; it is not included in the CISA KEV catalog. Based on the description, the attack vector is remote; any network‑connected attacker can craft the POST request without authentication, making exploitation relatively straightforward. Because the flaw leads to internal host exposure, it poses critical risk for routers that are not otherwise protected. No special exploitation conditions are cited, so the vulnerability can affect all devices running the specified firmware without additional prerequisites.
OpenCVE Enrichment