ZeroHour

CVE-2026-51718

niche

Improper access control in TOTOLINK T6 allows unauthenticated DHCP reservation deletion

CVSS 3.1
9.8 critical
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-51718 is an improper access control flaw (CWE-284) in the delStaticDhcpRules function of TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, invoking the function without any authorization check. Successful exploitation deletes the router's static DHCP reservations, removing fixed IP address mappings that dependent hosts rely on; the flaw is scored 9.8 Critical (AV:N/AC:L/PR:N/UI:N). Any TOTOLINK T6 running the affected firmware whose web management interface is reachable by an attacker, such as units with remote administration exposed to the internet, is affected. No public proof-of-concept or confirmed exploitation is known; the issue is not in CISA's KEV catalog and EPSS estimates roughly a 0.3% probability of exploitation within 30 days.

What to do: Do not expose the T6 web management interface (the /cgi-bin/cstecgi.cgi endpoint) to untrusted networks, and review the router's static DHCP reservation list for unexpected deletions. Monitor TOTOLINK's support/downloads page for a firmware release after 4.1.5cu.748_B20211015 that addresses CVE-2026-51718 and upgrade promptly when one becomes available. With no public PoC and low EPSS, immediate risk is limited, but unauthenticated configuration-tampering flaws on exposed routers should still be mitigated quickly.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (the firmware build cited in the advisory; other affected builds are not specified in the available data)
Estimated exposure
nichelikely a few thousand devices at most (single consumer router model at one firmware build; public internet scans show only tens of thousands of TOTOLINK… — No install-base figures exist for this specific model, so the estimate relies on public scan data showing TOTOLINK's entire internet-exposed fleet is in the tens of thousands, of which one model at one build would be a small fraction.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove static DHCP reservations via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.