Impact
In the TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015 the NTPSyncWithHost routine handles time synchronization without requiring proper authentication. This allows an attacker who can reach the device over the network to send a crafted HTTP POST to "/cgi-bin/cstecgi.cgi" and modify the internal system clock. The official description does not explicitly state additional consequences; however, based on the nature of a time change, it is inferred that time‑dependent functions on the device could be affected, though impacts on log integrity or certificate validation are not confirmed by the CVE data.
Affected Systems
The vulnerability is confined to TOTOLINK T6 routers running firmware build 4.1.5cu.748_B20211015. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The flaw is an access control failure that can be exploited remotely via an unauthenticated web request. With a CVSS score of 9.1, this vulnerability falls into the critical severity range. While no EPSS score is available and the issue has not been added to the CISA KEV catalog, the absence of authentication means any host on the same network can alter the device clock. The potential for disruption combined with the simplicity of the attack vector suggests a high risk to devices that rely on accurate timekeeping.
OpenCVE Enrichment