CVE-2026-51719

TOTOLINK · T6

An access control flaw in the TOTOLINK T6 router allows unauthenticated remote attackers to delete URL filtering rules by sending a malicious POST request to the cgi-bin interface.

Executive summary

A critical access control vulnerability in TOTOLINK T6 routers allows unauthenticated attackers to bypass security policies by removing configured URL filters.

Vulnerability

The vulnerability exists within the delUrlFilterRules function, which fails to perform proper authentication checks. An unauthenticated attacker can exploit this by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to modify device security settings.

Business impact

The ability for an unauthenticated attacker to remove URL filtering rules directly undermines the security posture of the network. This could allow users to access restricted, malicious, or unauthorized content that the organization intended to block, potentially leading to malware infection or data exfiltration. With a CVSS score of 7.5, this high-severity vulnerability represents a significant risk to network integrity and policy enforcement.

Remediation

Immediate Action: Review the official TOTOLINK support portal for available firmware updates addressing this flaw; if no patch exists, restrict access to the device management interface to trusted internal networks only.

Proactive Monitoring: Monitor device logs for anomalous POST requests directed at /cgi-bin/cstecgi.cgi, particularly those originating from untrusted or external IP addresses.

Compensating Controls: Implement firewall rules to block external access to the device management interface and utilize network segmentation to isolate the router from public-facing exposure.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high impact of unauthorized security policy modification, organizations utilizing TOTOLINK T6 devices must prioritize securing the management interface immediately. Administrators should verify the current firmware version and apply any vendor-supplied security patches as soon as they are released to prevent potential exploitation.

More TOTOLINK CVEs

Sources