CVE-2026-51719: TOTOLINK T6 vulnerability
Incorrect access control in the delUrlFilterRules function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to remove URL filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Apply compensating access control for TOTOLINK T6 4.1.5cu.748_B20211015 by preventing unauthenticated access to /cgi-bin/cstecgi.cgi (e.g., restrict the endpoint to authenticated sessions / trusted management network at the network/WAF/ACL level).
Event History
Frequently Asked Questions
Who is exposed to this issue?
Devices running TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 are identified as affected. The vulnerable function can be reached without authentication.
What does an attacker need to exploit it?
An attacker needs to send a crafted POST request to /cgi-bin/cstecgi.cgi targeting the delUrlFilterRules function. No valid login credentials are required.
What is the impact of successful exploitation?
An attacker can remove URL filtering rules from the affected device, weakening or disabling configured URL-based access restrictions.