Impact
The vulnerability is an incorrect access control check in the setAccessDeviceCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. It allows an unauthenticated attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi and alter the device’s access‑device policies, potentially granting unauthorized administrative privileges.
Affected Systems
The affected product is the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. No other affected versions are listed in the CVE data.
Risk and Exploitability
Exploitability requires the ability to send an HTTP POST request to the vulnerable CGI endpoint. The CVSS score is not provided, EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The lack of a proper access control mechanism means that successful exploitation could lead to significant configuration changes and privilege escalation, but the likelihood of exploitation cannot be quantified from the available data.
OpenCVE Enrichment