CVE-2026-51729

TOTOLINK · T6

An access control flaw in the TOTOLINK T6 delDevice function allows unauthenticated attackers to delete managed slave devices via crafted POST requests.

Executive summary

The TOTOLINK T6 router contains a critical access control vulnerability that enables unauthenticated attackers to perform unauthorized device management actions.

Vulnerability

This vulnerability involves incorrect access control within the delDevice function, which is reachable via the /cgi-bin/cstecgi.cgi endpoint. An unauthenticated attacker can trigger this function to delete managed slave devices without requiring any administrative credentials.

Business impact

The ability for an unauthenticated attacker to arbitrarily delete managed slave devices presents a significant risk to network availability and integrity. Successful exploitation could lead to denial of service for connected network segments and disrupt critical infrastructure operations. Given the CVSS score of 9.1, this vulnerability is categorized as critical due to the ease of remote access and the high impact on operational control.

Remediation

Immediate Action: Consult the official TOTOLINK support portal to verify if a firmware update exists for the T6 model and apply it immediately. If no patch is currently available, restrict access to the web management interface to trusted internal networks only.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at /cgi-bin/cstecgi.cgi, specifically those originating from untrusted or external IP addresses.

Compensating Controls: Implement strict firewall rules to block external access to the device management interface, ensuring that administrative functions are only accessible from secure, internal management VLANs.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical nature of this vulnerability and the lack of authentication required to trigger the deletion of slave devices, immediate action is required. Organizations utilizing the TOTOLINK T6 should isolate the management interface from the public internet and contact the vendor for guidance on available firmware updates to mitigate this risk.

More TOTOLINK CVEs

Sources