Impact
TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 contain an incorrect access control flaw in the setUPnPCfg function. The flaw allows an unauthenticated attacker to change the UPnP service state by sending a crafted POST request to /cgi-bin/cstecgi.cgi. Based on the description, it is inferred that enabling or disabling UPnP may expose the device to further network exploits or allow indirect access to internal services. The vulnerability is rooted in a flaw in access control mechanisms, matching CWE-284.
Affected Systems
The affected product is the TOTOLINK T6 router with firmware build 4.1.5cu.748_B20211015. No other vendors or versions are listed in the CNA data.
Risk and Exploitability
The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker who can reach the router's web interface (local or remote) can exploit the flaw by sending a crafted POST request, because no authentication is enforced. The lack of authentication checks makes exploitation trivial for such attackers. The CVSS score of 9.1 indicates high severity, and the potential impact on network exposure and denial of critical services warrants prompt remediation.
OpenCVE Enrichment