Impact
An incorrect authorization check in the setWiFiAdvancedCfg function of TOTOLINK T6 firmware allows an attacker without any credentials to send a specially crafted POST request to /cgi-bin/cstecgi.cgi. This request can alter wireless configuration settings and degrade network performance or connectivity for users of the device.
Affected Systems
The vulnerability affects TOTOLINK routers running firmware model T6 with version 4.1.5cu.748_B20211015. Only this specific build is known to be vulnerable.
Risk and Exploitability
The EPSS score is not available and the CVE is not listed in the CISA KEV catalog, indicating no public exploitation data. The attack vector is inferred to be remote, via HTTP over the router’s web interface, requiring no authentication. Once an attacker can reach the vulnerable endpoint, they can manipulate wireless settings, potentially causing service interruption or bandwidth degradation. The lack of authentication controls represents a critical weakness, but the exploitation complexity appears low for anyone with network access to the router.
OpenCVE Enrichment