Impact
The vulnerability is an incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can craft a POST request to /cgi-bin/cstecgi.cgi and remove firewall filter rules, undermining the device’s security policy. This loss of integrity could allow malicious traffic to bypass the router’s firewall protection.
Affected Systems
The affected product is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendors or products are listed.
Risk and Exploitability
The flaw can be exploited remotely without authentication, meaning any device reachable on the network is exposed. Although EPSS data are unavailable and the vulnerability is not listed in the KEV catalog, the lack of authentication required suggests a high likelihood of exploitation once a router is online. The CVSS score of 9.1 indicates a high severity problem, confirming the potential impact of the flaw.
OpenCVE Enrichment