CVE-2026-51716
moderateUnauthenticated Port-Forwarding Rule Deletion in TOTOLINK T6 Router Firmware
CVE-2026-51716 is an incorrect access control flaw (CWE-284) in the delPortForwardRules function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015, which does not properly enforce authentication before modifying port-forwarding settings. An unauthenticated attacker with network access to the router's web management interface can send a crafted POST request to /cgi-bin/cstecgi.cgi to delete existing port-forwarding rules. The attacker gains integrity-only impact: they can wipe or disrupt the router's NAT/port-forwarding configuration (for example, breaking inbound access to services hosted behind the router), with no confidentiality impact, privilege escalation, or code execution indicated by the CVSS scoring. Only TOTOLINK T6 routers running the listed firmware version are affected, and devices whose management interface is not reachable from untrusted networks are less exposed. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently assigns a low 0.3% probability of exploitation within 30 days (18th percentile).
What to do: Check the running firmware version in the T6 web UI, and until TOTOLINK publishes a fixed firmware (none specified in available data), restrict the management interface by disabling WAN-side/remote management and limiting admin access to trusted LAN hosts. Monitor for unauthenticated POST requests to /cgi-bin/cstecgi.cgi invoking delPortForwardRules, and check the vendor's support site for updated T6 firmware.
| TOTOLINK T6 router (firmware) | 4.1.5cu.748_B20211015 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the delPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to delete port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.