Impact
A flaw in the UploadCustomModule routine of TOTOLINK T6 firmware allows an attacker to send a specially crafted POST request to /cgi-bin/cstecgi.cgi without authentication. Successfully exploiting the flaw results in the upload of a custom CGI module that runs with the privileges of the web server, giving the attacker the ability to execute arbitrary commands, exfiltrate data, or compromise the entire device. The core weakness is an improper restriction on who may upload modules, which can be leveraged to gain full control of the device. The impact is equivalent to remote code execution and can be used to persist malicious code or establish back‑doors.
Affected Systems
TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015 are affected. No other vendor products are listed, but any device running this same firmware build shares the vulnerability.
Risk and Exploitability
The vulnerability is exploitable from any network the device exposes, and the attack does not require prior credentials. No CVSS or EPSS score is publicly available, and the vulnerability is not catalogued in the CISA KEV list. However, the nature of the bug—unauthenticated upload of executable content—makes it highly dangerous; an attacker who can reach the device could install malicious modules and maintain persistent access.
OpenCVE Enrichment