Impact
An unauthenticated attacker can reduce the wireless power output or crash the device by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. The vulnerability stems from improper access control within the setWiFiSignalCfg function, allowing any network user to invoke critical power‑management commands without authentication. The resulting loss of connectivity represents a pure availability attack and can be executed remotely over an HTTP interface.
Affected Systems
The flaw affects TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No other product versions are currently documented as affected.
Risk and Exploitability
Because the attacker does not need any credentials, the risk is high for any device exposed to the network that can reach its management interface. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, but the lack of authentication combined with a remote HTTP endpoint makes exploitation straightforward. The CVSS score is 7.5, indicating a high severity. The potential impact is a complete loss of wireless connectivity or a full system crash, disrupting all devices relying on the router.
OpenCVE Enrichment