CVE-2026-51724

TOTOLINK · T6

A flaw in the TOTOLINK T6 delSmartQosCfg function allows unauthenticated remote attackers to delete Smart QoS configurations through a crafted POST request to the cgi-bin directory.

Executive summary

A critical access control vulnerability in TOTOLINK T6 routers allows unauthenticated attackers to modify system configurations, posing a significant risk to network integrity.

Vulnerability

The vulnerability exists due to incorrect access control within the delSmartQosCfg function. An unauthenticated attacker can execute a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to remove critical Quality of Service rules from the device.

Business impact

The ability for an unauthenticated user to alter router configurations presents a severe threat to operational continuity. By removing QoS rules, an attacker can intentionally degrade network performance, prioritize malicious traffic, or disrupt critical business communication services. With a CVSS score of 9.8, this vulnerability is classified as critical due to the lack of required authentication and the potential for total impact on the device integrity.

Remediation

Immediate Action: Consult the official TOTOLINK support portal to determine if a firmware update addressing this specific access control flaw is available for the T6 model.

Proactive Monitoring: Review system logs for suspicious POST requests targeting /cgi-bin/cstecgi.cgi and monitor for unexpected changes to network traffic prioritization or QoS settings.

Compensating Controls: Implement strict network segmentation to ensure the router management interface is not exposed to the public internet, and utilize a firewall to restrict access to the web management console to trusted IP addresses only.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical CVSS severity rating, organizations utilizing the TOTOLINK T6 should prioritize this vulnerability immediately. If a vendor-supplied patch is not yet available, restrict administrative access to the router interface to prevent remote exploitation. Users must monitor vendor advisories closely for upcoming firmware releases to permanently remediate this insecure configuration management flaw.

More TOTOLINK CVEs

Sources