CVE-2026-51729: TOTOLINK T6 vulnerability
Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to request deletion of a managed slave device via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker does not need to authenticate. Exploitation requires sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint that reaches the vulnerable delDevice function.
Which systems are known to be affected?
The reported affected product is the TOTOLINK T6 running firmware version 4.1.5cu.748_B20211015. The provided information does not identify other affected versions or models.
What is the practical impact of successful exploitation?
An unauthenticated attacker can request deletion of a managed slave device. The available information does not state whether the deletion is immediate, reversible, or requires network-adjacent access.