CVE-2026-51720: TOTOLINK T6 vulnerability
Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to remove firewall filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TOTOLINK T6to a version that resolves this vulnerability.Fixed in 4.1.5cu.748_B20211015
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
An attacker does not need to authenticate. Exploitation requires sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint.
What is the practical impact of successful exploitation?
A successful attacker can remove firewall IP/port filter rules through the delIpPortFilterRules function. This can weaken network traffic restrictions configured on the affected device.
Which product version is identified as affected?
The reported affected version is TOTOLINK T6 firmware 4.1.5cu.748_B20211015.