CVE-2026-51720
largeUnauthenticated firewall rule deletion in TOTOLINK T6 router firmware
CVE-2026-51720 is an incorrect access control flaw (CWE-284) in the delIpPortFilterRules function of the web management interface on TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker who can reach the router's HTTP service can trigger it by sending a crafted POST request to /cgi-bin/cstecgi.cgi that invokes delIpPortFilterRules without any credentials or user interaction. A successful request deletes the device's configured IP/port firewall filter rules, silently weakening or removing the network's traffic filtering (integrity impact; scored 9.1 critical). Anyone operating an affected TOTOLINK T6 with the management interface reachable from an untrusted network — for example WAN-facing remote management or untrusted LAN/Wi-Fi clients — is affected. Exploitation is not currently documented: there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS puts the 30-day exploitation probability at about 0.3% (21st percentile).
What to do: If your T6 runs firmware 4.1.5cu.748_B20211015, upgrade to the latest TOTOLINK release when a fixed version is published (no fixed version is identified in the available data), and in the meantime disable WAN-side remote management and restrict the web UI to trusted LAN hosts. Review the router's configured IP/port filter rules for unexplained deletions, and monitor for unauthenticated POST requests to /cgi-bin/cstecgi.cgi that reference delIpPortFilterRules.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (the referenced firmware version; no other version ranges specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove firewall filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.