Impact
The delWiFiAclRules function in TOTOLINK T6 firmware accepts a crafted POST request to /cgi-bin/cstecgi.cgi without requiring authentication. A malicious actor can therefore delete Wi‑Fi access‑control list entries, potentially allowing unauthorized devices to connect or causing a denial of service by clearing legitimate rules. This flaw is an improper access‑control failure that directly affects network integrity and availability.
Affected Systems
The vulnerability affects TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No additional affected versions are specified in the available data.
Risk and Exploitability
The CVSS score of 9.1 indicates high severity, and the lack of authentication requirement allows any network‑connected actor to trigger the removal of ACL rules by sending a crafted POST payload to the web interface. The EPSS score is not available and the flaw is not listed in CISA KEV, suggesting limited early exploitation activity, but the high impact and straightforward attack path present a significant threat to network security.
OpenCVE Enrichment