Impact
An incorrect access control in the setWiFiBasicCfg function allows an attacker who can reach the router’s management interface to send a crafted POST request to /cgi‑bin/cstecgi.cgi and change the primary Wi‑Fi settings, including SSID, security mode, or password. This grants unauthorized control of the wireless network and can lead to denial of service, man‑in‑the‑middle attacks, or compromise of device integrity. The weakness is an improper authorization check on configuration requests.
Affected Systems
The flaw is present in TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No other vendors or product versions are listed in the advisory. The vulnerability is specific to the consumer‑grade router’s configuration interface exposed to the local network.
Risk and Exploitability
The CVSS score is not reported and no EPSS data is available, so the quantified risk is uncertain. Based on the description, it is inferred that the attack vector is an untrusted user who can reach the router’s local network and send a POST request to the management interface at /cgi‑bin/cstecgi.cgi. Attackers who can reach the router’s management interface can exploit the flaw without authentication, indicating a high likelihood of successful exploitation from the local network or any network that can access the management interface. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation at the time of the advisory.
OpenCVE Enrichment