Impact
The setParentalRules function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 allows an unauthenticated attacker to alter parental‑control settings by sending a crafted POST request to /cgi-bin/cstecgi.cgi. This flaw permits the attacker to modify or bypass access restrictions applied to any user on the network, effectively altering the router’s security posture. The impact is a loss of confidentiality for traffic that should have been filtered or blocked, and the potential for denial‑of‑service if parental controls are disabled. The weakness is a classic improper access control issue (CWE‑284).
Affected Systems
The vulnerability affects the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendors or product variants are listed, restricting the scope to this specific configuration.
Risk and Exploitability
No CVSS or EPSS score is provided, so the exact exploitation probability cannot be quantified. An attacker only needs to send an HTTP POST request to the router’s web interface, typically reachable on the LAN, to exploit the flaw. Because authentication is not required, any device connected to the local network could try the attack. While the vulnerability is not listed in the CISA KEV catalog, the lack of a KEV status does not mean it is benign; the exposure of the router’s administrative interface and the absence of authentication make the risk moderate to high, contingent on whether the interface is exposed externally or restricted to trusted devices.
OpenCVE Enrichment