Impact
Incorrect access control in the killProcess function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015 permits any network user to craft a POST request to /cgi-bin/cstecgi.cgi and terminate essential services, resulting in loss of availability for those services. The flaw does not provide code execution or data exfiltration capabilities, but it can be used to disrupt services on the device.
Affected Systems
The vulnerability affects TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No other versions or vendors are documented as impacted.
Risk and Exploitability
The CVSS score and EPSS data are not available, yet the lack of authentication allows an attacker on the same network to exploit the flaw at any time. The flaw is not listed in the CISA KEV catalog, but its simplicity means it could be abused to cause denial of service in targeted attacks. No public exploit has been reported.
OpenCVE Enrichment