Impact
The vulnerability lies in improper access control within the setWiFiRepeaterCfg function, allowing an unauthenticated attacker to repoint a TOTOLINK T6 device to an attacker‑controlled upstream Wi‑Fi by sending a crafted POST request to /cgi-bin/cstecgi.cgi. This weakness is a Classic Incorrect Access Control flaw (CWE‑284), which can lead to unauthorized network configuration changes, potential loss of connectivity, and the device acting as an untrusted point of access to external networks.
Affected Systems
Affected are TOTOLINK T6 wireless repeaters running firmware version 4.1.5cu.748_B20211015. No other vendors or product versions are listed as impacted by the issue.
Risk and Exploitability
Because the flaw allows unauthenticated modification of the upstream Wi‑Fi settings, an attacker only needs network reachability to the device’s management interface. The EPSS score is < 1% and the issue is not listed in KEV, suggesting no publicly available exploit at the time of analysis, but the lack of authentication means a successful exploitation is trivially feasible if the attacker can reach the target. The CVSS score of 9.1 indicates critical severity.
OpenCVE Enrichment