Impact
TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 suffer from an improper access control flaw in the showSyslog function. An attacker who is not authenticated can craft a POST request to /cgi-bin/cstecgi.cgi and retrieve recent system logs without needing credentials. The exposed logs may contain configuration details, user data or network topology, giving an attacker valuable information for further attacks. This weakness is an instance of improper access control (CWE-284).
Affected Systems
The vulnerability affects the TOTOLINK T6 router model with firmware 4.1.5cu.748_B20211015. No other vendors or product variants are listed in the current data.
Risk and Exploitability
Based on the description, it is inferred that an unauthenticated attacker can trigger the vulnerable endpoint from any device that can reach the router’s management interface, such as within the same local network or a DMZ. The CVSS score of 7.5 reflects a high severity impact on confidentiality. The EPSS score is less than 1%, indicating a low current exploitation likelihood, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the simplicity of the exploit warrants proactive mitigation to prevent potential information leakage.
OpenCVE Enrichment