Impact
The flaw in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 occurs in the setPortForwardRules function where an authentication check is omitted. An attacker can craft a POST request to /cgi-bin/cstecgi.cgi and create or modify forwarding entries, enabling the router to expose internal network services to the outside world. This improper access control (CWE‑284) directly compromises the confidentiality and integrity of internal resources.
Affected Systems
TOTOLINK’s T6 router running firmware version 4.1.5cu.748_B20211015 is the only product identified as vulnerable in the CVE record.
Risk and Exploitability
The high CVSS score of 9.8 reflects severe impact, yet the EPSS score of less than 1% suggests a low probability of real‑world exploitation. Because the vulnerability is not listed in CISA’s KEV catalog, no widespread exploitation has been observed. Based on the description, it is inferred that an unauthenticated attacker who can reach the router’s management interface—such as a user connected to the local network or an external party exploiting a exposed administrative port—can send the crafted POST request and create a port forwarding rule that exposes LAN services outside the network.
OpenCVE Enrichment