Impact
The delUrlFilterRules function in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 lacks proper authentication checks, allowing an attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi and delete any configured URL filtering rule. This unauthorized deletion can remove protective measures that block access to malicious or restricted sites, compromising the router’s security configuration. The vulnerability represents a classic example of CWE‑284: Improper Access Control.
Affected Systems
Only the TOTOLINK T6 router running the aforementioned firmware version is documented as affected. No other vendors or product lines appear in the CNA data or public advisories.
Risk and Exploitability
The flaw carries a CVSS score of 7.5 and an EPSS score of <1%, indicating high severity but low exploitation likelihood. The vendor’s catalogue does not list the issue in CISA’s KEV database. Based on the description, it is inferred that the attacker needs network access to the router’s internal management interface to trigger the vulnerable CGI endpoint, making the attack vector likely local network or compromised device. Exploitation is trivial once access is obtained, but the impact is confined to configuration integrity rather than code execution.
OpenCVE Enrichment