Impact
The vulnerability resides in the setApWiFiSchCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An attacker that is not authenticated can send a crafted POST request to /cgi-bin/cstecgi.cgi and modify the device’s wireless availability windows. This allows the attacker to turn off Wi‑Fi during periods when legitimate users expect connectivity or rearrange the schedule deterministically. The primary consequence is a denial of wireless service for affected devices, potentially disrupting business or personal access that depends on those networks.
Affected Systems
This flaw affects the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other products, vendors or versions were explicitly listed as impacted in the advisory.
Risk and Exploitability
The CVE lacks published CVSS or EPSS scores, indicating limited publicly available exploitation data. However, the description specifies that the crafted POST request can be sent to a standard CGI endpoint, suggesting that the attack can be performed directly to the device over the local network or, if the device is externally reachable, from the internet. The vulnerability carries an unverified yet credible risk of remote denial of service because an unauthenticated attacker can alter essential configuration settings without any additional privileges. No KEV listing has been reported, so the vulnerability is not currently publicized in the CISA catalog.
OpenCVE Enrichment