Impact
An incorrect access control check in the FirmwareUpgrade routine of TOTOLINK T6 firmware allows an unauthenticated attacker to delete Wi‑Fi schedule entries by sending a specially crafted POST request to /cgi-bin/cstecgi.cgi. The attacker can therefore alter the device’s scheduling logic or remove scheduled connections, potentially disrupting planned network usage or disabling key functions without requiring any credentials. This vulnerability focuses on improper authorization, enabling configuration changes that affect the availability and reliability of the network service.
Affected Systems
The flaw is present in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. Devices running this build are directly impacted by the weakness; no other vendor or product versions are indicated as affected in the available data.
Risk and Exploitability
The vulnerability can be exercised by any entity that can reach the router’s web interface, sending a POST request without authenticating. The EPSS score of <1% indicates a very low exploitation probability, yet the CVSS score of 9.8 reflects a critical severity that could allow an attacker to delete Wi‑Fi schedule entries. The flaw is not listed in the CISA KEV catalog. Because modification of network scheduling can disrupt planned connectivity, the risk remains high and mitigation is advised.
OpenCVE Enrichment