Impact
TOTOLINK routers running firmware version 4.1.5cu.748_B20211015 contain a flaw in the getSlaveUpdate function of the /cgi-bin/cstecgi.cgi CGI that allows an unauthenticated attacker to send a crafted POST request. The vulnerability removes the access check that normally protects this endpoint, letting the attacker query the status of a slave upgrade and interfere with the upgrade bookkeeping process. The behavior can expose information about the device’s firmware state and potentially allow the attacker to disrupt future firmware updates by corrupting or bypassing upgrade tracking.
Affected Systems
The vulnerability affects TOTOLINK T6 routers that have firmware version 4.1.5cu.748_B20211015 installed. Only that firmware build is known to contain the flaw; other product families or firmware releases from TOTOLINK have not been reported to be impacted.
Risk and Exploitability
The CVSS score is 9.8, and EPSS is < 1%, indicating limited operational data. The vulnerability is not listed in the CISA KEV catalog. Attack requires a crafted POST to /cgi-bin/cstecgi.cgi and is only possible from an unauthenticated source that can reach the router’s management interface. While public exploit code is not available, the flaw can be used to gain significant knowledge of the upgrade environment and potentially disrupt firmware updates. The risk is considered low to moderate, but remediation should occur promptly when a patch is released.
OpenCVE Enrichment