Impact
This vulnerability resides in the setRoamingCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. A malicious actor can send a crafted POST request to /cgi-bin/cstecgi.cgi without authentication and change the device’s roaming configuration. The altered settings can disrupt network connectivity or cause a denial of service for legitimate devices. This failure is an example of improper access control as defined by CWE-284.
Affected Systems
The vendor TOTOLINK’s T6 series running firmware build 4.1.5cu.748_B20211015 is affected. No other models or firmware revisions are noted in the advisory.
Risk and Exploitability
Because the flaw permits unauthenticated modification of device settings, any network exposed to the management interface represents a high‑risk target. No CVSS or EPSS metric is published, and the vulnerability is not included in the CISA KEV catalog, indicating no publicly known exploits as of now. Attackers can employ a simple crafted HTTP POST to trigger the change, but the lack of a patch means the critical risk remains until the vendor issues a fix. The likely attack vector is the device’s internal web interface accessible over the network.
OpenCVE Enrichment