Impact
The vulnerability resides in the setWiFiEasyGuestCf function of the TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. Unauthorized users can send a specially crafted HTTP POST request to the /cgi-bin/cstecgi.cgi endpoint, triggering the function without authentication. The attacker can create new guest wireless access points or weaken existing guest network settings such as SSID, encryption type, or security key. Based on the description, it is inferred that these changes could allow an attacker or an outsider to connect to the guest network and potentially access internal resources through lateral movement or eavesdropping.
Affected Systems
The vulnerability is present in TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. Other devices in the same firmware family may also be affected if they ship with the same setWiFiEasyGuestCf implementation, which is an inference drawn from the firmware similarity.
Risk and Exploitability
The likely attack vector is a web‑based POST request that can be sent from any host able to reach the router’s admin interface, meaning the vulnerability is exploitable without credentials. The EPSS score of <1% indicates a very low probability of exploitation at present, but the CVSS score of 9.1 signals high severity. The flaw is not listed in the CISA KEV catalog, and no public exploit has been documented; however, the potential to alter guest network configuration in an unauthenticated manner warrants prompt assessment and mitigation.
OpenCVE Enrichment