Impact
The setStorageCfg function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an access control flaw that allows any unauthenticated client to send a crafted POST request to /cgi-bin/cstecgi.cgi and change storage‑related service settings. This flaw could let an attacker enable or disable persistent storage, alter data retention policies, or otherwise disrupt the device’s normal operation, impacting availability and potentially exposing stored data.
Affected Systems
This vulnerability affects TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. The specific affected component is the setStorageCfg routine exposed via the cstecgi CGI interface.
Risk and Exploitability
Because the flaw permits unauthenticated manipulation of the device’s configuration, an attacker can exploit it without needing prior credentials or special permissions, making deployment straightforward. The CVSS score of 9.8 and an EPSS score of <1% indicate a severe vulnerability that is unlikely to be widely exploited currently, but its impact remains significant. The vulnerability is not listed in CISA’s KEV catalog, so no publicly documented exploits are known at this time.
OpenCVE Enrichment