CVE-2026-51720

9.1

TOTOLINK · T6

An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to delete firewall filter rules via a crafted POST request.

Executive summary

A critical access control vulnerability in TOTOLINK T6 routers allows unauthenticated attackers to disable firewall protections, posing a severe risk to network security.

Vulnerability

This vulnerability resides in the delIpPortFilterRules function of the web management interface. It permits any unauthenticated attacker to remove firewall filter rules by sending a malicious POST request to the /cgi-bin/cstecgi.cgi endpoint.

Business impact

Successful exploitation of this flaw allows an attacker to strip away firewall rules, effectively exposing the local network to unauthorized traffic and potential secondary attacks. Given the CVSS score of 9.1, this is classified as a critical risk that could lead to full compromise of internal network segments or sensitive data exfiltration by bypassing existing security perimeters.

Remediation

Immediate Action: Consult the official TOTOLINK support portal for firmware updates addressing this flaw, as the manufacturer has not yet released a specific patch version. If no update is available, restrict access to the web management interface to trusted internal IP addresses only.

Proactive Monitoring: Monitor device logs for unusual POST requests directed at /cgi-bin/cstecgi.cgi and keep a close watch for unexpected changes to firewall configuration settings.

Compensating Controls: Deploy a network-level firewall or Web Application Firewall (WAF) to block unauthorized access to the device management interface from external or untrusted sources.

Exploitation status

Public Exploit Available: Unknown (No confirmed public exploit in available data)

Analyst recommendation

The severity of this vulnerability necessitates immediate attention to prevent unauthorized modification of network security policies. Administrators should prioritize restricting access to the management interface and verify the device firmware status against the vendor website to identify if a fix has been issued.

More TOTOLINK CVEs

Sources