Impact
The vulnerability resides in the setLanCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and bypass access control, allowing the attacker to change LAN network settings such as IP address, subnet mask, or gateway. This flaw grants the attacker the ability to disrupt network connectivity, potentially leading to denial of service or network hijacking. The weakness is a classic access‑control bypass.
Affected Systems
The affected product is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendors or product versions are listed as affected.
Risk and Exploitability
The vulnerability has an EPSS score of < 1% and is not listed in the CISA KEV catalog. The lack of publicly provided exploitation metrics suggests that exploitation has not been observed in the wild as of this analysis. The CVSS score of 4.3 indicates a moderate impact for the affected firmware. The flaw can be triggered simply by sending an HTTP POST request to the exposed CGI endpoint, so the attack vector is remote over the local network or the internet if the router port is forwarded. The impact is significant for any environment that relies on the router for secure LAN configuration because an attacker who can change network settings may isolate devices, create routing loops, or redirect traffic. Given the severity of the potential operational disruption, immediate attention is recommended to mitigate the risk.
OpenCVE Enrichment