Impact
An access control flaw in the informSlaveUpdate function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015 allows an attacker who can send HTTP POST requests to /cgi-bin/cstecgi.cgi to initiate mesh slave update coordination without any authentication. The flaw stems from the function failing to validate that the caller has appropriate privileges before forwarding the update command, thereby permitting a rogue requester to trigger an update cycle. While the description does not confirm further compromise, forcing a device into an update state could disrupt network operations or pave the way for additional attacks if the update process is exploitable.
Affected Systems
The affected product is TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No other vendor or product variants were identified in the current data set.
Risk and Exploitability
EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, so publicly known exploit activity is unknown. The attack vector is achievable via a standard HTTP POST to the CGI endpoint, which can be performed from any host that can reach the device on the relevant port. Because no authentication is enforced, the technical barrier is low; an attacker only needs network access to the device. The overall risk can be considered moderate to high until an official patch is applied or mitigation steps reduce exposure.
OpenCVE Enrichment