Impact
The vulnerability is an incorrect access control in the setOpModeCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015, enabling unauthenticated attackers to modify the device operating mode by sending a crafted POST request to /cgi-bin/cstecgi.cgi. This flaw permits attackers to change operating mode without authentication, potentially leading to disruption of network services, unauthorized mode switching, or other configuration changes that affect network availability and integrity. The weakness corresponds to improper access controls (CWE-284).
Affected Systems
TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015 are affected. The vendor is TOTOLINK and the specific firmware version is explicitly mentioned in the advisory. No additional product variants or versions are listed in the available data.
Risk and Exploitability
No publicly available CVSS or EPSS score is provided, and the vulnerability is not listed in CISA KEV, indicating no known exploitation at this time. The likely attack vector is remote; an attacker could craft a POST request over the local network or, if the interface is exposed externally, over the internet. The absence of exploitation evidence suggests a moderate risk for this flaw until an official firmware fix is released. Within the current dataset, the estimated exploitation likelihood cannot be quantified beyond its potential to allow unauthorized configuration changes.
OpenCVE Enrichment