Impact
The vulnerability is an incorrect access control flaw in the clearSyslog function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. It allows an unauthenticated attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi and permanently erase system logs. By removing or corrupting these logs, the attacker can deny investigators evidence of prior activities and hinder forensic analysis, effectively destroying the device’s audit trail while leaving no obvious indication of compromise.
Affected Systems
Affected devices are TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. No other vendors or product lines are mentioned.
Risk and Exploitability
The lack of authentication required for the attack means an adversary with network access to the router can easily exploit it. Although the EPSS score is currently unavailable and the vulnerability is not listed in CISA’s KEV catalog, the simplicity of the payload and the absence of complex prerequisites give it a moderate likelihood of exploitation. The attack vector is a network‑based POST request to a known CGI endpoint that can redirect or remove log data without permission.
OpenCVE Enrichment