Impact
The totallink T6 router contains an access control flaw in the setWiFiScheduleCfg function, allowing an attacker who can reach the web interface to send a crafted POST request to /cgi-bin/cstecgi.cgi and modify the Wi‑Fi availability schedule without authentication. The attacker could effectively turn the wireless network off or on at will, resulting in a loss of connectivity for all users attached to the router.
Affected Systems
The flaw is found in TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. It is unknown whether earlier or later firmware revisions contain the same oversight, so any devices using that exact build are certainly impacted.
Risk and Exploitability
Because the vulnerability can be exercised from an unauthenticated session, no special credentials are required. The EPSS score is not available, but the vulnerability is publicly documented and easily exploitable through a simple HTTP POST. The KEV catalog does not list this issue, yet the high impact on network availability warrants prompt action. The attack path consists of locating the vulnerable router, establishing an HTTP connection, and issuing the POST request with a crafted payload to alter the schedule. Once successful, the attacker controls when the wireless network is operational.
OpenCVE Enrichment