Impact
This vulnerability arises from incorrect access control in the delWiFiScheduleCfg function. An attacker who can reach the device over the network can send a crafted POST request to /cgi-bin/cstecgi.cgi and delete entries from the Wi‑Fi schedule. The flaw enables removal of scheduled network settings without any authentication. The impact is limited to loss of scheduled configurations and potential disruption of automated connections, but does not grant full control of the device or access to sensitive data.
Affected Systems
TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 is affected.
Risk and Exploitability
The CVSS score for this issue is not reported, and the EPSS score is unavailable. It is not listed in the CISA KEV catalog, but the lack of authentication required means the attack can be performed from any network host that can reach the device’s management interface. The vulnerability is exploitable via a simple HTTP POST, requiring no special privileges. Once exploited, only Wi‑Fi schedule entries can be removed, which could disrupt connectivity but does not expose broader system control.
OpenCVE Enrichment