Impact
This vulnerability is an incorrect access control flaw in the setManualDialCfg function that allows an attacker to manipulate the WAN dial state without authentication. By sending a crafted POST request to /cgi-bin/cstecgi.cgi, an attacker who can reach the device over the network can change the dial state, effectively reconfiguring how the router connects to the internet. The flaw could enable an attacker to disrupt connectivity, bypass connectivity restrictions, or force the router to use an alternate service provider, thereby compromising availability and potentially confidentiality if related authentication mechanisms are weakened.
Affected Systems
The affected product is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendor or product variants are listed. The vulnerability is specific to this firmware release and affects all devices that have not applied the update that fixes the access control issue.
Risk and Exploitability
The attack vector is inferred to be through the exposed web interface, as the exploit requires sending a crafted POST request to the CGI script. The CVSS score is 9.1, indicating high severity. The EPSS score of less than 1% suggests a very low exploitation probability, and the vulnerability is not listed in CISA's KEV catalog. Nonetheless, because the flaw allows unauthenticated configuration changes, the risk is significant—any network user with access to the router’s management interface can reconfigure the WAN dial state. Mitigation requires patching or restricting the exposed interface.
OpenCVE Enrichment