Impact
The vulnerability exists in the setPairCfg function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015, where improper access control allows an unauthenticated attacker to send a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. This flaw enables the attacker to alter the mesh pairing state of the device, potentially disabling legitimate peer connectivity or disrupting network operation. The weakness is classified as Improper Access Control (CWE‑284). The CVSS score of 9.1 indicates a high severity, underscoring the potential for denial of service or unauthorized manipulation of the device’s mesh behavior.
Affected Systems
Compatible with TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. Any device that exposes the /cgi-bin/cstecgi.cgi CGI script and has the setPairCfg functionality enabled is affected.
Risk and Exploitability
The attack vector is inferred to be remote, requiring the ability to send an HTTP POST request to the vulnerable endpoint. Because the request is unauthenticated, an attacker with network or external access to the router can exploit it. The EPSS score is < 1%, indicating a low but non‑zero probability of exploitation. The CVSS score of 9.1 highlights the high severity of the flaw and its potential to disrupt legitimate mesh operations. The vulnerability is not listed in CISA KEV, so no designated exploitation campaigns have been reported yet, but the risk remains due to the lack of authentication and the public exposure of the endpoint.
OpenCVE Enrichment