CVE-2026-51724
largeUnauthenticated access-control flaw in TOTOLINK T6 Smart QoS
CVE-2026-51724 is an incorrect access control flaw (CWE-284) in the delSmartQosCfg function of the TOTOLINK T6 router's web API at /cgi-bin/cstecgi.cgi. An unauthenticated attacker who can reach the management interface can send a crafted POST request to that endpoint and delete the device's Smart QoS rules without logging in. The documented impact is tampering with the router's traffic-shaping configuration (wiped QoS rules and potential network performance changes), although the flaw carries a 9.8 critical CVSS 3.1 score. Any TOTOLINK T6 running firmware 4.1.5cu.748_B20211015 is affected, particularly units whose admin interface is reachable from the WAN or another untrusted network. There is currently no known exploitation, no public proof-of-concept, and the CVE is not in CISA's KEV; EPSS estimates about a 0.3% probability of exploitation within 30 days.
What to do: Check any internet-reachable TOTOLINK T6 for firmware 4.1.5cu.748_B20211015 and upgrade to the latest TOTOLINK firmware once a patched release is published (no fixed version is named in the disclosure). Until patched, block unauthenticated access to /cgi-bin/cstecgi.cgi by disabling WAN-side remote management or restricting admin access to trusted hosts, and re-verify Smart QoS settings for unexpected deletions.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 (the only firmware version named in the disclosure; other builds not confirmed) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.