Impact
The vulnerability originates from incorrect access control (CWE-284) in the setSmartQosCfg function of TOTOLINK T6. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to alter Quality of Service settings, causing traffic handling degradation on the device.
Affected Systems
TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No vendor or product names are provided beyond the internal firmware identifier.
Risk and Exploitability
The flaw can be triggered without authentication, suggesting remote exploitation is possible via the router’s public or locally accessible CGI endpoint. The EPSS score indicates a low exploitation probability (<1%) and the vulnerability is not listed in the CISA KEV catalog, implying limited exploitation activity. With a CVSS score of 4.3, the vulnerability represents moderate severity and, with no publicly disclosed exploit code, the primary risk is a potential denial of service through QoS misconfiguration.
OpenCVE Enrichment