Impact
An unauthenticated attacker can alter the browsing policy on a Totolink T6 router by sending a specially crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. The vulnerability originates from improper access control in the setUrlFilterRules function, allowing the attacker to set or modify URL filtering rules without logging in. This capability enables traffic redirection, blocking, or other policy changes that could compromise the confidentiality, integrity, or availability of the network. The weakness is a classic example of unauthorized modification due to missing authentication, identified as CWE‑284.
Affected Systems
The affected device is a Totolink T6 router running firmware version 4.1.5cu.748_B20211015, the only vendor and product details provided. No additional vendor or version information is disclosed.
Risk and Exploitability
The CVSS score of 9.1 signals a high‑severity flaw, while the EPSS score of less than 1% indicates a low but non‑zero probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV database, which means no publicly known, actively exploited incidents have been reported yet. The likely attack vector is a local network intrusion where an attacker can reach the router’s management interface; the exploit requires no authentication and involves sending a single POST request with crafted payloads, making it straightforward for anyone with network access to the router.
OpenCVE Enrichment