Impact
An incorrect access control check in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 allows an unauthenticated attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi trigger the clearTracerouteLog function. This function erases the device’s traceroute logs, removing valuable forensic evidence and hindering troubleshooting without affecting device configurations or network connectivity.
Affected Systems
This flaw targets TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No other vendors or product lines are mentioned in the advisory as affected.
Risk and Exploitability
The vulnerability is exploitable remotely via an unauthenticated HTTP POST. EPSS is not provided and the issue is not listed in CISA’s KEV catalog, yet the absence of an authentication barrier and the potential for log deletion represent a moderate to high operational risk for environments where audit trails are critical. The CVSS score is not supplied, but the impact on traceability alone warrants significant concern.
OpenCVE Enrichment