Impact
The flaw resides in the LoadDefSettings routine of TOTOLINK T6 firmware 4.1.5cu.748_B20211015, where access control is not enforced. This omission lets an unauthenticated attacker craft a POST request to /cgi-bin/cstecgi.cgi and trigger a device configuration reset and reboot. The defect is an instance of improper access control, allowing loss of configuration state and potential service disruption.
Affected Systems
All devices running the affected firmware version of the TOTOLINK T6 router – firmware 4.1.5cu.748_B20211015 – are impacted. No other TOTOLINK models or firmware versions are known to be affected.
Risk and Exploitability
Unauthenticated or low‑privilege attackers can execute the exploit without needing credentials or additional access. Based on the description, it is inferred that the vulnerability is purely remote and does not require privileged privileges, leading to a high attack surface. The CVSS score of 9.8, combined with an EPSS score of less than 1 %, and the fact that it is not listed in CISA KEV, underline the severe operational impact of being able to reset configuration and reboot the device.
OpenCVE Enrichment