Impact
TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 contain an incorrect access control flaw in the showSyslog function, which allows an attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi and obtain recent system logs without authentication. The information revealed may include sensitive configuration details, user data, or network topology, potentially enabling further reconnaissance or exploitation. The weakness is an instance of improper access control.
Affected Systems
The affected system is the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. No other vendors or product variants are explicitly listed.
Risk and Exploitability
The attack vector is straightforward: an unauthenticated attacker can trigger the vulnerable endpoint by sending a POST request from any device that can reach the router's management interface, such as within the same local network or from a DMZ. The CVSS score is not provided, but the exposure of logs without authentication indicates a serious confidentiality risk. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting it may not yet have public exploits, yet the ease of exploitation warrants proactive mitigation.
OpenCVE Enrichment