Impact
The vulnerability is an incorrect access control in the setWiFiEasyCfg function, enabling an unauthenticated attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi and reconfigure or disable wireless networks. This can disrupt network connectivity, alter security settings, and potentially expose the network to further attacks by changing SSID, password, or security mode.
Affected Systems
TOTOLINK T6 wireless router running firmware version 4.1.5cu.748_B20211015 is affected.
Risk and Exploitability
The CVSS score is 9.8 and the EPSS score is < 1%, so an exact risk metric can be calculated. However, the vulnerability allows unauthenticated remote modification of critical wireless settings without requiring authentication, indicating a high severity. Attackers can exploit the flaw via an HTTP or HTTPS POST request from any host that can reach the router’s management interface. The vulnerability is not listed in the CISA KEV catalog, but the lack of a patch or official advisory suggests that the risk remains significant until remedial action is taken.
OpenCVE Enrichment