CVE-2026-51715
largeUnauthenticated MAC filter deletion flaw in TOTOLINK T6 router
TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an incorrect access control flaw (CWE-284) in the delMacFilterRules function, which handles deletion of MAC address filter rules without verifying that the requester is authenticated. An attacker who can reach the router's web interface sends a crafted POST request to /cgi-bin/cstecgi.cgi invoking this function and no credentials or user interaction are required. Successful exploitation erases the router's MAC filter rules, which can re-admit previously blocked devices to the Wi-Fi/LAN and weaken the network's device-level access controls. Owners and operators of TOTOLINK T6 routers running this firmware are affected, particularly any unit whose management interface is reachable from the WAN. No public proof-of-concept is known, the issue is not in CISA's KEV, and the EPSS score of 0.3% indicates currently low expected exploitation activity.
What to do: Check the firmware version on any TOTOLINK T6 in your environment; if it is 4.1.5cu.748_B20211015, watch the vendor's site for a corrected firmware release, as no fixed version is specified in the available data. As an interim mitigation, do not expose the router's management interface to the WAN (disable remote management and restrict port 80/443 access), and periodically review the MAC filter rules for unexplained deletions, since the affected endpoint requires no authentication.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 (the only firmware build named in the advisory; other versions not confirmed) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.