Impact
The flaw resides in the LoadDefSettings routine of TOTOLINK T6 firmware 4.1.5cu.748_B20211015, where access control is not enforced. This omission lets an unauthenticated attacker craft a POST request to /cgi-bin/cstecgi.cgi and trigger a device configuration reset and reboot. The defect is an instance of improper access control, allowing loss of configuration state and potential service disruption.
Affected Systems
All devices running the affected firmware version of the TOTOLINK T6 router – firmware 4.1.5cu.748_B20211015 – are impacted. No other TOTOLINK models or firmware versions are known to be affected.
Risk and Exploitability
Unauthenticated or low‑privilege attackers can execute the exploit without needing credentials or additional access. Based on the description, it is inferred that the vulnerability is purely remote and does not require privileged privileges, leading to a high attack surface. While EPSS data is unavailable and the vulnerability is not listed in KEV, the severity implied by the ability to reset configuration and reboot the device indicates a significant operational risk.
OpenCVE Enrichment