Impact
The vulnerability resides in the setIpPortFilterRules function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015, where access controls are not enforced, allowing an unauthenticated attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi and alter firewall rules. This permits an attacker to bypass or modify network protection policies, potentially enabling unauthorized network access or data exfiltration. The weakness is an improper authorization flaw (CWE-284).
Affected Systems
Affected devices are TOTOLINK T6 routers operating firmware version 4.1.5cu.748_B20211015. No other vendor or product versions are listed in the CVE data.
Risk and Exploitability
The CVE lacks an assigned CVSS or EPSS score, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack vector is network-based, requiring no authentication and a crafted POST payload, making exploitation relatively straightforward for an attacker who can reach the device. Because the attacker can change firewall rules, the risk of compromise and network disruption is high even in the absence of a quantified severity metric.
OpenCVE Enrichment