Impact
The vulnerability exists in the delVlanCfg routine of TOTOLINK T6 firmware 4.1.5cu.748_B20211015, where a missing access control check allows an attacker to send a specially crafted POST request to /cgi-bin/cstecgi.cgi and cause the router to delete existing VLAN configuration entries. The deletion is performed without authentication, meaning the attacker does not need any credentials and only requires network reachability to the router’s web management interface. This loss of VLAN entries can eliminate network isolation, allowing traffic that should be segregated to cross VLAN boundaries or trigger a denial‑of‑service by removing critical VLANs.
Affected Systems
The issue specifically affects TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No other vendor or product releases are known to be impacted, and TOTOLINK has not yet published a vendor‑specific fix. The flaw is limited to the router’s management interface exposed on the local or remote network.
Risk and Exploitability
The EPSS score for this vulnerability is not available, and it is not listed in CISA’s KEV catalog, so the measurable likelihood of exploitation remains unknown. The attack vector is inferred to be local or remote access to the router’s web‑management interface, which is common in residential or small office environments. Because the flaw removes authorization checks, an attacker who can reach the interface can potentially bypass VLAN segmentation and cause widespread network disruption. In the absence of a public exploit, the risk is considered moderate awaiting a vendor‑issued fix.
OpenCVE Enrichment