CVE-2026-51731: TOTOLINK T6 vulnerability
Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TOTOLINK T6to a version that resolves this vulnerability.Fixed in 4.1.5cu.748_B20211015
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of TOTOLINK T6 running firmware version 4.1.5cu.748_B20211015 are identified as affected. An attacker must be able to send a request to the device's CGI endpoint.
Does exploitation require authentication?
No. The issue allows unauthenticated attackers to remove VLAN entries by sending a crafted POST request to /cgi-bin/cstecgi.cgi.
What is the impact of successful exploitation?
A successful attacker can remove VLAN entries through the delVlanCfg function. This can alter VLAN segmentation and disrupt the network configuration.