Impact
The setParentalRules function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 allows an unauthenticated attacker to alter parental‑control settings by sending a crafted POST request to /cgi-bin/cstecgi.cgi. This flaw permits the attacker to modify or bypass access restrictions applied to any user on the network, effectively altering the router’s security posture. The impact is a loss of confidentiality for traffic that should have been filtered or blocked, and the potential for denial‑of‑service if parental controls are disabled. The weakness is a classic improper access control issue (CWE‑284).
Affected Systems
The vulnerability affects the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendors or product variants are listed, restricting the scope to this specific configuration.
Risk and Exploitability
The CVSS score of 9.1 indicates a critical severity. The EPSS score is less than 1%, suggesting a low likelihood of exploitation in the wild, but the absence of authentication means any device on the LAN can attempt it. Attack requires only sending a crafted HTTP POST request to /cgi-bin/cstecgi.cgi on the router’s web interface. Because the vulnerability is not listed in KEV, no known widespread exploitation is documented, yet the high severity and easy access warrant immediate attention.
OpenCVE Enrichment