CVE-2026-51715
TOTOLINK · T6
An access control flaw in the TOTOLINK T6 router allows unauthenticated attackers to delete MAC filter rules by sending a malicious POST request to a specific CGI endpoint.
Executive summary
A critical access control vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to bypass security configurations by deleting MAC filter rules.
Vulnerability
The vulnerability exists within the delMacFilterRules function of the device firmware. An unauthenticated attacker can trigger this function by submitting a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint, resulting in the unauthorized removal of established MAC filtering rules.
Business impact
The ability for an unauthenticated attacker to manipulate network security rules poses a significant threat to internal network integrity. By removing MAC filters, an attacker can bypass device-level access restrictions, potentially allowing unauthorized hardware to connect to the network or facilitating further lateral movement. Given the CVSS score of 9.8, this vulnerability represents a critical risk that could lead to full compromise of network access control mechanisms.
Remediation
Immediate Action: Verify if your device is running firmware version 4.1.5cu.748_B20211015 and consult the official TOTOLINK support portal for any available firmware updates to address this access control flaw.
Proactive Monitoring: Monitor device traffic logs for suspicious POST requests directed at /cgi-bin/cstecgi.cgi, particularly those originating from untrusted or external IP addresses.
Compensating Controls: Restrict administrative access to the router management interface by disabling remote management and ensuring the device is not directly exposed to the public internet.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability presents a severe risk to network security by exposing administrative controls to unauthenticated actors. Organizations utilizing the TOTOLINK T6 router must prioritize patching or, if a patch is unavailable, immediately isolate the device from external network exposure to prevent unauthorized configuration changes.