Impact
The vulnerability is an incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and change the Wi‑Fi Protected Setup (WPS) availability setting. The attacker can enable or disable WPS without authentication, potentially exposing the network to brute‑force attacks or disrupting legitimate WPS usage. This results in unauthorized configuration modification, affecting the confidentiality of network connectivity and the availability of configuration services.
Affected Systems
Affected device: TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other product versions are mentioned and no other vendors are affected.
Risk and Exploitability
The vulnerability is local to the device’s management interface and can be triggered without authentication; the attack vector is network based. An attacker who can reach the device can modify WPS settings by sending a POST request to a known CGI endpoint. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, so the exact likelihood of exploitation is uncertain. Nonetheless, any unauthenticated attacker with network access can disrupt or enable WPS, leading to denial of service or unauthorized access if the router is misconfigured.
OpenCVE Enrichment