Impact
The flaw resides in the setNtpCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. It is an access control weakness that permits an unauthenticated user to send a crafted POST request to /cgi-bin/cstecgi.cgi and change the router's NTP settings. This unauthorized modification can alter how the device synchronizes its clock and maps to improper access control (CWE‑284). Based on the description, it is inferred that altering the NTP configuration could affect time‑related operations such as logging, authentication, and scheduled tasks.
Affected Systems
TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015 are affected. No other product variants or firmware releases are listed as impacted; vendor and product identification is unavailable.
Risk and Exploitability
The likely attack vector is an unauthenticated network attacker sending a crafted HTTP POST request to /cgi-bin/cstecgi.cgi. No authentication or strict input validation is performed, so any host that can reach the router's web interface can modify the NTP settings. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The risk is highest for devices exposed to the internet or insecure local networks. The weakness allows an attacker to influence device time, which could undermine time‑dependent processes.
OpenCVE Enrichment