Impact
The vulnerability involves incorrect access control in the setRemoteCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and gain exposure to the WAN‑side administration interface. This gives the attacker the ability to modify router settings, potentially compromising confidentiality, integrity, and availability of the network.
Affected Systems
The affected product is the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. No other versions or vendors are listed in the current data.
Risk and Exploitability
The vulnerability is remote and requires no local access, making it an unauthenticated remote‑side attack. The CVSS score of 9.1 indicates critical severity. No EPSS score is available and the issue is not listed in the CISA KEV catalog, but the high impact of exposing administrative controls suggests a serious risk. Because the attack path is straightforward—sending a crafted POST request—the likelihood of exploitation remains uncertain but potentially significant.
OpenCVE Enrichment