Impact
The flaw exists in the function that sets a wireless mesh name on a specific TOTOLINK T6 device. Because the call does not enforce proper authentication, any network‑connected client can send a crafted POST request to the designated CGI endpoint and change the name of a mesh entry. This unauthorized modification can confuse network management, undermine inventories, or serve as a foothold for further exploitation if an attacker can manipulate configuration settings. The weakness is a classic case of improper access control.
Affected Systems
TOTOLINK T6 devices running firmware version 4.1.5cu.748_B20211015 are affected. The vulnerability is tied specifically to the setWiFiMeshName function reachable at /cgi-bin/cstecgi.cgi.
Risk and Exploitability
The absence of an EPSS score leaves the likelihood of exploitation uncertain, but the vulnerability allows unauthenticated modification without additional authentication. KEV does not list this issue, so no current evidence exists that it is actively exploited. However, the unchanged firmware means the attack is trivially reachable on any device still using the vulnerable build. The CVSS score is not provided, but the vectors suggest a high severity for configuration integrity and availability.
OpenCVE Enrichment