Impact
An incorrect access control check in the UploadFirmwareFile function permits an attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi on a TOTOLINK T6 router that is running firmware version 4.1.5cu.748_B20211015. Because the check is bypassed, an unauthenticated user can upload a malicious firmware image. Once the device accepts the image, the attacker gains complete control over the router, enabling arbitrary code execution, persistent compromise, or denial of service. The vulnerability forms the core of the device’s firmware update mechanism and therefore represents a high‑impact flaw.
Affected Systems
Devices built on the TOTOLINK T6 platform that are deployed with firmware 4.1.5cu.748_B20211015 are affected.
Risk and Exploitability
The flaw can be triggered over the network by any party that can reach the router’s HTTP interface, without credentials or authentication. Because the EPSS score is not available and the vulnerability is not listed in KEV, the exact exploitation probability is unknown, but the impact of successful exploitation is severe, providing full firmware replacement authority. Since the attack vector is purely remote and unauthenticated, defenders must treat the condition as a high‑risk exposure until a patch is applied or a mitigation is enforced.
OpenCVE Enrichment