Impact
The SystemSettings function in TOTOLINK T6 firmware (4.1.5cu.748_B20211015) implements an incorrect access control that allows unauthenticated attackers to retrieve administrative import and export endpoint information by sending a crafted POST request to /cgi-bin/cstecgi.cgi. This flaw exposes sensitive configuration data and reflects an improper access control weakness.
Affected Systems
TOTOLINK T6 routers or modems running firmware version 4.1.5cu.748_B20211015 are affected. The vulnerability is specific to the SystemSettings CGI endpoint exposed by the router’s management interface.
Risk and Exploitability
The vulnerability enables unauthenticated disclosure of configuration information and can be exploited by any networked attacker with knowledge of the endpoint. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating that the exploitation likelihood is currently unknown but the potential impact remains significant. Attackers need only send a POST request to the CGI endpoint; no further prerequisites are stated. The vulnerability is therefore considered a moderate to high risk until a patch is applied.
OpenCVE Enrichment