CyberRota Analysis
AI-GeneratedTOTOLINK T6 version 4.1.5cu.748_B20211015 is vulnerable due to improper access control in the getSysStatusCfg function, allowing unauthenticated attackers to extract sensitive information, including operational details and network configurations, through a specially crafted POST request. Organizations using this router model should prioritize remediation to prevent potential data exposure and unauthorized access to their network. Immediate action is recommended for users handling sensitive data or operating in regulated environments.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Incorrect access control in the getSysStatusCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as operation mode, firmware version, serial number, WAN/LAN IP addresses, WiFi SSID, encryption keys, and connected client statistics via sending a crafted POST request to /cgi-bin/cstecgi.cgi.