CVE-2026-51719
moderateUnauthenticated URL filter rule deletion in TOTOLINK T6 router
TOTOLINK T6 router firmware 4.1.5cu.748_B20211015 contains an improper access control flaw (CWE-284) in the delUrlFilterRules function of its web management service. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to invoke this function without any credentials. Successful exploitation deletes URL filtering rules configured on the router, silently weakening or disabling web-filtering policy on networks behind the device, with no confidentiality or availability impact. Any T6 unit running the named firmware is affected, especially where the management web interface is reachable from the WAN or from untrusted clients. No public proof-of-concept or in-the-wild exploitation is known; EPSS currently estimates only about a 0.3% probability of exploitation within 30 days and the issue is not in CISA's KEV catalog.
What to do: Check whether your T6 runs firmware 4.1.5cu.748_B20211015 and consult TOTOLINK support for a patched release, since no fixed version is specified in the available data. Until then, do not expose the router's management interface to the WAN (disable remote management or restrict it to trusted hosts) and audit existing URL filter rules for unexplained deletions. Defenders can also watch logs for unauthenticated POST requests to /cgi-bin/cstecgi.cgi referencing delUrlFilterRules.
| TOTOLINK T6 wireless router | 4.1.5cu.748_B20211015 (firmware version named in the advisory; whether other firmware versions are affected is not stated in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the delUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove URL filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.