Impact
The vulnerability is an incorrect access control flaw in the setWanIeCfg function of a TOTOLINK router. By sending a crafted POST request to /cgi-bin/cstecgi.cgi, an unauthenticated attacker can reconfigure the device's uplink settings. This unauthorized modification can lead to disruption of network connectivity, potential denial of service, or enable further compromise by altering routing behavior.
Affected Systems
The affected product is the TOTOLINK T6 running firmware version 4.1.5cu.748_B20211015. No other vendors or products are listed. The scope is limited to this specific firmware build and device model.
Risk and Exploitability
The vulnerability does not have an EPSS score or CVSS score available, and it is not listed in CISA KEV. The exploit is a simple HTTP POST request that requires no authentication, making it trivially exploitable by anyone with network access to the router. Because the attacker can alter fundamental network settings, the risk to confidentiality, integrity, and availability is significant and should be treated as high.
OpenCVE Enrichment