ZeroHour

CVE-2026-51715

large

Unauthenticated MAC filter deletion flaw in TOTOLINK T6 router

CVSS 3.1
9.8 critical
EPSS
<1%p28
Published
()
Modified
AI analysis

TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an incorrect access control flaw (CWE-284) in the delMacFilterRules function, which handles deletion of MAC address filter rules without verifying that the requester is authenticated. An attacker who can reach the router's web interface sends a crafted POST request to /cgi-bin/cstecgi.cgi invoking this function and no credentials or user interaction are required. Successful exploitation erases the router's MAC filter rules, which can re-admit previously blocked devices to the Wi-Fi/LAN and weaken the network's device-level access controls. Owners and operators of TOTOLINK T6 routers running this firmware are affected, particularly any unit whose management interface is reachable from the WAN. No public proof-of-concept is known, the issue is not in CISA's KEV, and the EPSS score of 0.3% indicates currently low expected exploitation activity.

What to do: Check the firmware version on any TOTOLINK T6 in your environment; if it is 4.1.5cu.748_B20211015, watch the vendor's site for a corrected firmware release, as no fixed version is specified in the available data. As an interim mitigation, do not expose the router's management interface to the WAN (disable remote management and restrict port 80/443 access), and periodically review the MAC filter rules for unexplained deletions, since the affected endpoint requires no authentication.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (the only firmware build named in the advisory; other versions not confirmed)
Estimated exposure
largeon the order of tens of thousands of internet-exposed TOTOLINK devices, with the T6 subset plausibly in the thousands to tens of thousands (estimate; exact T6… — TOTOLINK is a widely sold budget consumer/SOHO router brand, and public internet scans (e.g., Shodan/FOFA) have historically shown tens of thousands of TOTOLINK devices with web management interfaces exposed to the internet, of which the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.