Impact
The flaw is an incorrect access control check in the setWiFiBasicCfg function, which allows an unauthenticated attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi and change the primary Wi‑Fi configuration of a TOTOLINK T6 router. The impact is that the attacker can modify the SSID, security mode, or password, giving them full control over the wireless network, potentially diverting legitimate traffic, enabling man‑in‑the‑middle attacks, or causing denial of service by disabling the network. This weakness is identified as an improper authorization check (CWE‑284). The CVSS score of 9.8 categorises the vulnerability as critical.
Affected Systems
The vulnerability affects only TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No other products or vendors are reported as impacted. The flaw resides in the router’s local management interface and is therefore limited to devices that expose that interface over a local or otherwise trusted network.
Risk and Exploitability
With a CVSS score of 9.8 the severity is critical, but the EPSS score of <1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploits. Based on the description it is inferred that the attack vector is an attacker who can reach the router’s management interface over the local or any network that can access that interface, and that the attacker need not authenticate to exploit the flaw. Therefore, the risk is high for any unprotected local or remote access to the management interface.
OpenCVE Enrichment