Impact
This vulnerability is an incorrect access control flaw in the setManualDialCfg function that allows an attacker to manipulate the WAN dial state without authentication. By sending a crafted POST request to /cgi-bin/cstecgi.cgi, an attacker who can reach the device over the network can change the dial state, effectively reconfiguring how the router connects to the internet. The flaw could enable an attacker to disrupt connectivity, bypass connectivity restrictions, or force the router to use an alternate service provider, thereby compromising availability and potentially confidentiality if related authentication mechanisms are weakened.
Affected Systems
The affected product is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendor or product variants are listed. The vulnerability is specific to this firmware release and affects all devices that have not applied the update that fixes the access control issue.
Risk and Exploitability
The attack vector is inferred to be through the exposed web interface, as the exploit requires sending a POST request to a CGI script. No EPSS or CVSS scores are available, so the quantitative severity cannot be determined from the supplied data. The vulnerability is not listed in CISA's KEV catalog, indicating that no widespread known exploits have been reported. Nonetheless, because the flaw allows unauthenticated configuration changes, the risk is significant—any network user with access to the router’s management interface can execute the exploit. Mitigation requires patching or restricting the exposed interface.
OpenCVE Enrichment