Impact
An incorrect access control check in the FirmwareUpgrade routine of TOTOLINK T6 firmware allows an unauthenticated attacker to delete Wi‑Fi schedule entries by sending a specially crafted POST request to /cgi-bin/cstecgi.cgi. The attacker can therefore alter the device’s scheduling logic or remove scheduled connections, potentially disrupting planned network usage or disabling key functions without requiring any credentials. This vulnerability focuses on improper authorization, enabling configuration changes that affect the availability and reliability of the network service.
Affected Systems
The flaw is present in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. Devices running this build are directly impacted by the weakness; no other vendor or product versions are indicated as affected in the available data.
Risk and Exploitability
The vulnerability can be exercised by any entity that can reach the router’s web interface, sending a POST request without authenticating. No EPSS score is provided and the vulnerability is not listed in the CISA KEV catalog, so the overall exploit probability remains uncertain. The absence of a CVSS score prevents an exact severity assessment, but the lack of authentication requirements and the ease of manipulation suggest that an attacker with network access could readily exploit the issue. Timely remediation or mitigation is advised to prevent unauthorized configuration changes.
OpenCVE Enrichment