Impact
The vulnerability exists in the setPairCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015, where improper access control allows an unauthenticated attacker to send a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. This flaw enables the attacker to alter the mesh pairing state of the device, potentially disabling legitimate peer connectivity or disrupting network operation. The weakness is classified as Improper Access Control (CWE‑284). No CVSS score is currently reported, so the quantitative severity level is unknown but the impact can lead to denial of service or unauthorized manipulation of the device’s mesh behavior.
Affected Systems
Compatible with TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. Any device that exposes the /cgi-bin/cstecgi.cgi CGI script and has the setPairCfg functionality enabled is affected.
Risk and Exploitability
The attack vector is inferred to be remote, requiring the ability to send an HTTP POST request to the vulnerable endpoint. Because the request is unauthenticated, an attacker with network or external access to the router can exploit it. No EPSS score is available and the vulnerability is not listed in CISA KEV, leaving the exploitation probability uncertain. However, the potential for unauthorized configuration change suggests that any exposed device is at risk until mitigated.
OpenCVE Enrichment