Impact
A flaw in the setStaticDhcpRules function of TOTOLINK firmware T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to add or change static DHCP rules by sending a crafted POST request to /cgi-bin/cstecgi.cgi. The vulnerability is an incorrect access control restriction violation (CWE‑284). It grants attackers the ability to alter the DHCP configuration that devices use to obtain IP addresses, enabling unauthorized changes to network address assignments.
Affected Systems
Devices running TOTOLINK firmware T6 4.1.5cu.748_B20211015 are impacted. The flaw exists in the setStaticDhcpRules functionality accessed via the /cgi-bin/cstecgi.cgi endpoint.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity issue. The EPSS score is less than 1 %, suggesting a low probability of active exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Attackers exploit the flaw by issuing a specially crafted HTTP POST request to /cgi-bin/cstecgi.cgi without authentication, a likely web‑based attack vector. Successful exploitation results in unauthorized modification of DHCP settings, directly impacting network configuration control.
OpenCVE Enrichment