Impact
The delWiFiAclRules function in TOTOLINK T6 firmware accepts a crafted POST request to /cgi-bin/cstecgi.cgi without requiring authentication. A malicious actor can thus remove Wi‑Fi access‑control list entries, potentially opening the network to unauthorized devices or causing a denial of service by clearing legitimate rules. This flaw represents an improper access‑control failure that directly impacts network integrity and availability.
Affected Systems
The vulnerability affects TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No additional affected versions are specified in the available data.
Risk and Exploitability
The EPSS score is not available, and the flaw is not listed in CISA KEV, suggesting limited early exploitation activity. Attackers must reach the router’s web management interface, craft a valid POST payload, and can do so without authentication. While no public exploits are reported, the lack of authentication allows any network‑connected actor to trigger the removal of ACL rules, presenting a significant threat to network security.
OpenCVE Enrichment