CVE-2026-51718
TOTOLINK · T6
TOTOLINK T6 routers contain an access control flaw in the delStaticDhcpRules function, permitting unauthenticated attackers to delete static DHCP reservations via a crafted POST request.
Executive summary
A critical access control vulnerability in TOTOLINK T6 routers allows unauthenticated attackers to disrupt network configurations, posing a significant risk to network availability and management.
Vulnerability
This is an improper access control vulnerability located within the delStaticDhcpRules function. The flaw allows an unauthenticated attacker to execute unauthorized administrative actions by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint.
Business impact
The ability for an unauthenticated attacker to modify static DHCP reservations can lead to significant network disruption, including IP address conflicts and the loss of connectivity for critical infrastructure devices. Given the CVSS score of 9.8, this vulnerability is classified as critical because it provides an attacker with the capability to impact the integrity and availability of the network environment without requiring any prior authentication.
Remediation
Immediate Action: Consult the official TOTOLINK support portal for firmware availability and update to the latest provided version if a patch is released.
Proactive Monitoring: Monitor network traffic for unusual POST requests directed at /cgi-bin/cstecgi.cgi and review system logs for modifications to DHCP reservation tables.
Compensating Controls: Restrict access to the router management interface by ensuring it is not exposed to the public internet and by utilizing internal network segmentation to limit reachability.
Exploitation status
Public Exploit Available: No (exploit_available unknown).
Analyst recommendation
The severity of this vulnerability necessitates immediate attention to prevent potential service denial or unauthorized network manipulation. Administrators should prioritize securing the management interface of the affected TOTOLINK T6 devices and apply the necessary firmware updates as soon as the vendor provides a resolution.