Impact
The vulnerability resides in the setIptvCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and bypass authentication to alter IPTV service configuration. Because the configuration can be changed without authorization, the attacker could disrupt the IPTV service, redirect streams, or potentially expose sensitive network traffic, thereby compromising confidentiality, integrity, and availability of the service. The weakness is an improper access control flaw that permits unauthorized modification of system settings.
Affected Systems
The affected product is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other versions or product variants are explicitly listed in the CVE data. Organizations using this specific firmware should verify whether the router is deployed and assess exposure.
Risk and Exploitability
An inherent CVSS score of 9.1 demonstrates severe potential impact, while the EPSS score of < 1% indicates a low probability of exploitation at present. The vulnerability is exploitable remotely via the web interface without authentication, making the attack vector straightforward for an adversary with network access to the device. The lack of designation in the CISA KEV catalog suggests no active exploitation is currently reported, but the unauthorized configuration capability represents a high risk to network control and can enable further attacks. The risk remains significant due to the ease of exploitation and the potential impact on service availability. The likely attack vector is an unauthenticated POST to the router's web interface.
OpenCVE Enrichment