Impact
The flaw is an access‑control weakness (CWE‑284) in the setUpgradeFW routine of router firmware. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and trigger changes in the firmware‑upgrade workflow. The CVE description does not state that the attacker can force the router to install a specified firmware image; this inference is not confirmed. Nonetheless, the ability to manipulate the upgrade process could allow a malicious firmware image to be loaded, potentially compromising device integrity or enabling further compromise.
Affected Systems
Affected systems are not clearly defined in the CVE record. The description references a firmware build 4.1.5cu.748_B20211015 and a /cgi-bin/cstecgi.cgi endpoint, but no vendor, product, or version details are explicitly listed. Additional research may be required to determine which devices are affected.
Risk and Exploitability
The CVSS score of 9.1 indicates high severity, while the EPSS score of less than 1% signals a low probability of exploitation at present. The flaw is not listed in CISA’s KEV catalog. Authentication is bypassed, so an attacker only needs network access to the router’s web or management interface to trigger the firmware‑upgrade process from any location, making this a high‑risk issue pending a vendor fix.
OpenCVE Enrichment