Impact
The vulnerability resides in the delStaticDhcpRules function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and delete static DHCP reservations without authentication. This lack of access control allows any device that can reach the router’s management interface to alter critical network configuration. Removing reservations can cause IP conflicts, deny service to designated clients, or enable attackers to capture those addresses.
Affected Systems
Vendor TOTOLINK, product T6 running firmware 4.1.5cu.748_B20211015. No other affected versions are listed in the CVE data.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Although no CVSS value is provided, the attack can be conducted remotely via HTTP by an unauthenticated attacker with network access to the router. The exploitation path is straightforward: send a crafted POST request to the vulnerable CGI endpoint, causing the deletion of static DHCP reservations. The impact is immediate and could disrupt network connectivity or facilitate further attacks.
OpenCVE Enrichment