CVE-2026-51724: TOTOLINK T6 vulnerability
Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the /cgi-bin/cstecgi.cgi endpoint (e.g., block it from untrusted networks via firewall/ACL) to prevent unauthenticated POST requests that can remove Smart QoS rules.
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker able to send HTTP POST requests to the router's web management interface can exploit it. The described impact is removal of Smart QoS rules.
Which product version is identified as affected?
The issue is reported in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015.
What request path is involved?
The affected endpoint is /cgi-bin/cstecgi.cgi. Exploitation involves a crafted POST request targeting the delSmartQosCfg function.