Impact
In the TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015 the NTPSyncWithHost routine handles time synchronization without requiring proper authentication. This allows an attacker who can reach the device over the network to send a crafted HTTP POST to "/cgi-bin/cstecgi.cgi" and modify the internal system clock. Such an unauthorized time change can undermine log integrity, certificate validation, scheduled tasks, and other time‑dependent functions on the device, potentially creating gaps in audit trails or enabling persistence operations that rely on altered timestamps.
Affected Systems
The vulnerability is confined to TOTOLINK T6 routers running firmware build 4.1.5cu.748_B20211015. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The flaw is an access control failure that can be exploited remotely via an unauthenticated web request. While no EPSS score is available and the issue has not been added to the CISA KEV catalog, the absence of authentication means any host on the same network can alter the device clock. The potential for disruption combined with the simplicity of the attack vector suggests a high risk to devices that rely on accurate timekeeping.
OpenCVE Enrichment