Impact
The vulnerability resides in the setIpPortFilterRules function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015, where access controls are not enforced, allowing an unauthenticated attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi and alter firewall rules. This permits an attacker to bypass or modify network protection policies, potentially enabling unauthorized network access or data exfiltration. The weakness is an improper authorization flaw (CWE-284).
Affected Systems
Affected devices are TOTOLINK T6 routers operating firmware version 4.1.5cu.748_B20211015. No other vendor or product versions are listed in the CVE data.
Risk and Exploitability
The CVE has a CVSS score of 4.3, an EPSS score of < 1%, and is not listed in the CISA KEV catalog. Nevertheless, the attack vector is network-based, requiring no authentication and a crafted POST payload, making exploitation relatively straightforward for an attacker who can reach the device. Because the attacker can change firewall rules, the risk of compromise and network disruption remains high even though the quantified severity metric is moderate.
OpenCVE Enrichment