ZeroHour

CVE-2026-51716

moderate

Unauthenticated Port-Forwarding Rule Deletion in TOTOLINK T6 Router Firmware

CVSS 3.1
7.5 high
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2026-51716 is an incorrect access control flaw (CWE-284) in the delPortForwardRules function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015, which does not properly enforce authentication before modifying port-forwarding settings. An unauthenticated attacker with network access to the router's web management interface can send a crafted POST request to /cgi-bin/cstecgi.cgi to delete existing port-forwarding rules. The attacker gains integrity-only impact: they can wipe or disrupt the router's NAT/port-forwarding configuration (for example, breaking inbound access to services hosted behind the router), with no confidentiality impact, privilege escalation, or code execution indicated by the CVSS scoring. Only TOTOLINK T6 routers running the listed firmware version are affected, and devices whose management interface is not reachable from untrusted networks are less exposed. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently assigns a low 0.3% probability of exploitation within 30 days (18th percentile).

What to do: Check the running firmware version in the T6 web UI, and until TOTOLINK publishes a fixed firmware (none specified in available data), restrict the management interface by disabling WAN-side/remote management and limiting admin access to trusted LAN hosts. Monitor for unauthenticated POST requests to /cgi-bin/cstecgi.cgi invoking delPortForwardRules, and check the vendor's support site for updated T6 firmware.

Affected
TOTOLINK T6 router (firmware)4.1.5cu.748_B20211015
Estimated exposure
moderateplausibly on the order of 10,000-100,000 affected devices worldwide (estimated; T6-specific installed base unknown) — Public internet-wide scans have historically indexed tens of thousands of TOTOLINK routers overall, and the T6 is a consumer/SOHO model sold mainly through retail channels in Asia, the Middle East, and Europe, so the T6-specific share -…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the delPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to delete port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.