Impact
The vulnerability resides in the setDdnsCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi that bypasses the expected authentication check, allowing the attacker to toggle the dynamic DNS feature on or off.
Affected Systems
Devices from the TOTOLINK T6 series that are running firmware version 4.1.5cu.748_B20211015 are impacted. The vendor’s coordination pages reference this specific firmware release. No other firmware versions or devices have been identified as affected.
Risk and Exploitability
The vulnerability requires only unauthenticated network access to the device and does not rely on additional privileges or sophisticated exploitation steps, and is rated high with a CVSS score of 7.5. No public exploitation has been reported, and the vulnerability is not listed in the CISA KEV catalog. The endpoint is accessible over the network interface. The EPSS score of < 1% indicates a low likelihood of exploitation.
OpenCVE Enrichment