Impact
The vulnerability is an incorrect access control flaw in the delMacFilterRules function of TOTOLINK T6 (firmware 4.1.5cu.748_B20211015). Unauthenticated attackers can send a crafted POST request to /cgi-bin/cstecgi.cgi to delete MAC filter rules. Removing these rules lifts the enforced MAC address whitelist, which weakens network access control. The effect of allowing devices to connect without the whitelist is inferred from the function’s purpose, not explicitly stated in the advisory.
Affected Systems
The flaw affects TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 from the public build release. Devices using other firmware versions are not impacted.
Risk and Exploitability
The flaw can be exploited remotely by any host that can reach the router’s HTTP interface to submit a POST request, as no authentication is required. Exploitation requires only network connectivity to the management interface. The EPSS score is <1%, and the vulnerability is not listed in CISA KEV. The CVSS score of 9.8 marks it as critical. The attack vector is likely local network or any machine with access to the router’s web interface.
OpenCVE Enrichment