CVE-2026-51741
TOTOLINK · T6
TOTOLINK T6 routers contain an incorrect access control vulnerability in the clearDiagnosisLog function, allowing unauthenticated attackers to erase system logs via a crafted POST request.
Executive summary
A critical access control flaw in TOTOLINK T6 routers allows unauthenticated attackers to remotely clear diagnostic logs, potentially facilitating the concealment of malicious activity.
Vulnerability
This vulnerability involves incorrect access control within the clearDiagnosisLog function. Unauthenticated attackers can trigger this function by sending a specifically crafted POST request to the /cgi-bin/cstecgi.cgi endpoint.
Business impact
The ability for an unauthenticated attacker to manipulate system logs represents a significant security risk by enabling the clearing of evidence following a compromise. With a CVSS score of 9.8, this vulnerability is categorized as critical because it allows attackers to bypass auditing mechanisms and potentially maintain persistence or hide unauthorized actions, leading to complete loss of log integrity.
Remediation
Immediate Action: Contact the vendor or consult the official support portal for available firmware updates addressing this log manipulation flaw. If no update is available for version 4.1.5cu.748_B20211015, restrict network access to the administrative interface.
Proactive Monitoring: Monitor device traffic for suspicious POST requests targeting the /cgi-bin/cstecgi.cgi endpoint, especially those originating from untrusted or external IP addresses.
Compensating Controls: Implement strict firewall rules to prevent external access to the device management interface, ensuring only authorized internal management subnets can interact with the web server.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of this vulnerability and the absence of authentication requirements, administrators must prioritize securing affected TOTOLINK T6 devices immediately. Restricting external access to the management interface is the most effective temporary mitigation until a vendor-supplied patch is applied.
More TOTOLINK CVEs all →
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.8 (3.1)
- Analyst report written