Impact
The setVpnPassCfg function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an incorrect access‑control check, letting any actor send a crafted POST request to /cgi-bin/cstecgi.cgi and alter edge‑filtering settings. The vulnerability does not allow code execution or full takeover; instead, it reduces the firewall’s effectiveness, potentially exposing internal devices to traffic that would normally be blocked or logged. The weakness is localized to the router’s administrative management interface and requires only network connectivity to the device.
Affected Systems
Affected system is the TOTOLINK T6 router running the 4.1.5cu.748_B20211015 firmware build. No other versions are listed, but any device using this firmware revision is included.
Risk and Exploitability
The security flaw permits unauthenticated manipulation of firewall rules through a simple HTTP POST, and the CVSS score of 9.8 indicates a high severity. The success probability is high for an attacker who can reach the device over the network. The EPSS score is below 1% and the issue is not listed in the CISA KEV catalog, but the lack of authentication control makes it a serious operational risk. An attacker could use the weakened edge filtering to pass malicious traffic or perform other network‑based attacks from within or outside the local network.
OpenCVE Enrichment