Impact
The vulnerability stems from an access control flaw in the delPortForwardRules function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. Unauthenticated attackers can craft a POST request to /cgi-bin/cstecgi.cgi, causing incorrect permission checks to delete port-forwarding rules. This deletion can disrupt network traffic routing, potentially disabling forwarded services or redirecting traffic. The flaw is a classic example of missing authentication or authorization checks, compounding the risk for network administrators. The impact is limited to the scope of port-forwarding configuration; it does not grant full administrative access.
Affected Systems
The affected environment includes TOTOLINK T6 routers that are running the disclosed firmware version 4.1.5cu.748_B20211015. No additional vendor or product versions are explicitly enumerated in the CVE data. Administrators of any installations using this firmware should verify whether the router runs the stated firmware revision.
Risk and Exploitability
The CVSS score is not provided in the data, and the EPSS score is unavailable, meaning the likelihood of exploitation cannot be quantified. However, because the vulnerability requires only a crafted HTTP POST and provides no authentication, if an attacker can reach the router externally or via an internal network, the delete operation can be performed with ease. Since the issue is not listed in the CISA KEV catalog, there is no evidence of active exploitation, but the potential for accidental misconfiguration or malicious deletion remains. The lack of a proven exploit does not diminish the need for remediation, given the disruptive effect on port forwarding, which is a critical configuration for many home and small‑business networks.
OpenCVE Enrichment