CVE-2026-51718: TOTOLINK T6 vulnerability
Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to remove static DHCP reservations via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to /cgi-bin/cstecgi.cgi (e.g., via firewall/ACL/WAF) so only authenticated/authorized clients can reach it.
Event History
Frequently Asked Questions
What access does an attacker need to remove a static DHCP reservation?
No authentication is required. An attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi targeting the delStaticDhcpRules function.
Which deployment is confirmed to be affected?
The affected product and version identified in the available data is the TOTOLINK T6 running firmware 4.1.5cu.748_B20211015.
What is the impact of successful exploitation?
A successful attacker can remove static DHCP reservations. The available information does not state any additional impact beyond deletion of those reservations.