Impact
The vulnerability originates from incorrect access control in the setSmartQosCfg function. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and alter Quality of Service settings, resulting in traffic handling degradation on the device.
Affected Systems
TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No vendor or product names are provided beyond the internal firmware identifier.
Risk and Exploitability
The flaw can be triggered without authentication, suggesting remote exploitation is possible via the router’s public or locally accessible CGI endpoint. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, indicating low to moderate known exploitation activity. With no publicly disclosed exploit code, the primary risk is a potential denial of service through QoS misconfiguration.
OpenCVE Enrichment