Impact
The vulnerability resides in the clearDiagnosisLog function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and remove all stored diagnostics logs. This loss of evidence can hinder troubleshooting, obscure fault causes, and facilitate the concealment of malicious activity, but it does not provide direct code execution or broader system compromise. The flaw is a classic case of incorrect access control, which permits privileged actions to be performed by anyone with network access to the device.
Affected Systems
The affected product is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendors or product lines are listed as impacted in the current advisory.
Risk and Exploitability
EPSS score is < 1% and the vulnerability is not listed in CISA KEV. The CVSS score is 9.8, indicating a critical severity despite the limited impact of log deletion. Unauthenticated attackers can exploit the flaw by crafting a POST request to the CGI endpoint from any machine that can reach the router’s local network. No authentication or privileged credentials are required, making exploitation straightforward for network inside actors.
OpenCVE Enrichment