Impact
The vulnerability resides in the setWanCfg function of the TOTOLINK T6 firmware, where incorrect access control allows an unauthenticated attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi and modify upstream provisioning and connectivity settings. This flaw can result in remote alteration of WAN configurations, potentially causing service disruption or redirecting traffic to malicious endpoints, thereby compromising network availability and potentially exposing sensitive data to unintended parties.
Affected Systems
The flaw affects TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015.
Risk and Exploitability
The CVSS score of 9.1 indicates critical severity. EPSS is below 1%, suggesting low but nonzero exploitation probability. The flaw is not listed in the CISA KEV catalog, but the lack of authentication requirement presents a high risk for remote attackers. The likely attack vector is network-based; an attacker can send a crafted HTTP POST to /cgi-bin/cstecgi.cgi without credentials. The impact allows remote alteration of WAN configurations, potentially causing service disruption or redirecting traffic to malicious endpoints.
OpenCVE Enrichment