Impact
An incorrect access control in the delMacFilterRules function of TOTOLINK T6 allows an unauthenticated attacker to remove MAC filter rules by sending a crafted POST request to /cgi-bin/cstecgi.cgi. This deletion disables the enforced device whitelist, enabling any device to connect to the network without authorization and potentially compromise network resources.
Affected Systems
The vulnerability affects TOTOLINK T6 running firmware version 4.1.5cu.748_B20211015. Only this specific build contains the flaw, so check if your device uses that firmware and consider upgrading to a version that removes the error.
Risk and Exploitability
The flaw can be exploited remotely by any party that can reach the router’s HTTP interface and submit a POST request, as no authentication is required. The exploitation requires only the ability to send HTTP traffic to the target and is not dependent on privileged credentials. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, but the impact of completely disabling MAC address filtering poses a high risk to network security and integrity.
OpenCVE Enrichment