Impact
An incorrect access control check in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 allows an unauthenticated attacker to send a crafted POST request to /cgi-bin/cstecgi.cgi trigger the clearTracerouteLog function. This function erases the device’s traceroute logs, removing valuable forensic evidence and hindering troubleshooting without affecting device configurations or network connectivity.
Affected Systems
This flaw targets TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No other vendors or product lines are mentioned in the advisory as affected.
Risk and Exploitability
The vulnerability is exploitable remotely via an unauthenticated HTTP POST. EPSS is less than 1% and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 5.3 indicates moderate severity, and the lack of an authentication barrier combined with the ability to delete logs poses a notable operational risk for environments that rely on audit trails.
OpenCVE Enrichment