CVE-2026-51718
nicheImproper access control in TOTOLINK T6 allows unauthenticated DHCP reservation deletion
CVE-2026-51718 is an improper access control flaw (CWE-284) in the delStaticDhcpRules function of TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, invoking the function without any authorization check. Successful exploitation deletes the router's static DHCP reservations, removing fixed IP address mappings that dependent hosts rely on; the flaw is scored 9.8 Critical (AV:N/AC:L/PR:N/UI:N). Any TOTOLINK T6 running the affected firmware whose web management interface is reachable by an attacker, such as units with remote administration exposed to the internet, is affected. No public proof-of-concept or confirmed exploitation is known; the issue is not in CISA's KEV catalog and EPSS estimates roughly a 0.3% probability of exploitation within 30 days.
What to do: Do not expose the T6 web management interface (the /cgi-bin/cstecgi.cgi endpoint) to untrusted networks, and review the router's static DHCP reservation list for unexpected deletions. Monitor TOTOLINK's support/downloads page for a firmware release after 4.1.5cu.748_B20211015 that addresses CVE-2026-51718 and upgrade promptly when one becomes available. With no public PoC and low EPSS, immediate risk is limited, but unauthenticated configuration-tampering flaws on exposed routers should still be mitigated quickly.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (the firmware build cited in the advisory; other affected builds are not specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove static DHCP reservations via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.