Impact
TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 contains an incorrect access control flaw in the delSmartQosCfg function. An attacker who does not need prior authentication can send a specially crafted POST request to /cgi-bin/cstecgi.cgi and cause the device to delete Smart QoS rules. This loss of QoS configuration can alter traffic prioritization, potentially resulting in degraded network performance or denial of service for critical applications.
Affected Systems
The vulnerability affects the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. No other vendors or products are listed as affected.
Risk and Exploitability
The flaw can be exploited by any network host that can reach the router’s /cgi-bin/cstecgi.cgi endpoint, requiring only a crafted HTTP POST request. The EPSS score of < 1% indicates a low exploitation probability, but the CVSS score of 9.8 marks it as critical. Because the vulnerability lacks authentication, an attacker can delete Smart QoS rules from the device, potentially disrupting traffic prioritization and causing degraded network performance or denial of service for critical applications if the device is exposed to untrusted networks. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment