CVE-2026-51730
9.1TOTOLINK · T6
TOTOLINK T6 routers contain an incorrect access control vulnerability in the delWiFiAclRules function, allowing unauthenticated attackers to remove Wi-Fi ACL rules via crafted POST requests.
Executive summary
A critical access control vulnerability in TOTOLINK T6 routers allows unauthenticated attackers to bypass security restrictions and modify network configurations.
Vulnerability
The vulnerability exists within the delWiFiAclRules function, where insufficient access control checks permit an unauthenticated attacker to execute unauthorized actions by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint.
Business impact
The ability for an unauthenticated attacker to manipulate Wi-Fi Access Control List (ACL) rules poses a significant threat to network security. By removing these rules, an attacker can bypass established security policies, potentially granting unauthorized users access to the internal network. Given the CVSS score of 9.1, this vulnerability represents a high-severity risk that could lead to unauthorized network access and potential data exposure.
Remediation
Immediate Action: Review vendor documentation for firmware updates that address ACL control vulnerabilities and apply the latest available version provided by TOTOLINK.
Proactive Monitoring: Inspect web server access logs for suspicious POST requests targeting /cgi-bin/cstecgi.cgi or evidence of unauthorized modifications to Wi-Fi ACL settings.
Compensating Controls: Restrict access to the router management interface by ensuring it is not exposed to the public internet and by utilizing network segmentation to isolate management traffic from untrusted zones.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Due to the critical nature of this vulnerability and the ease of exploitation, administrators should treat this as a high-priority item. If a vendor-supplied patch is not yet available for your specific build, restrict access to the device management interface immediately to prevent remote exploitation attempts.