ZeroHour

CVE-2026-51724

large

Unauthenticated access-control flaw in TOTOLINK T6 Smart QoS

CVSS 3.1
9.8 critical
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-51724 is an incorrect access control flaw (CWE-284) in the delSmartQosCfg function of the TOTOLINK T6 router's web API at /cgi-bin/cstecgi.cgi. An unauthenticated attacker who can reach the management interface can send a crafted POST request to that endpoint and delete the device's Smart QoS rules without logging in. The documented impact is tampering with the router's traffic-shaping configuration (wiped QoS rules and potential network performance changes), although the flaw carries a 9.8 critical CVSS 3.1 score. Any TOTOLINK T6 running firmware 4.1.5cu.748_B20211015 is affected, particularly units whose admin interface is reachable from the WAN or another untrusted network. There is currently no known exploitation, no public proof-of-concept, and the CVE is not in CISA's KEV; EPSS estimates about a 0.3% probability of exploitation within 30 days.

What to do: Check any internet-reachable TOTOLINK T6 for firmware 4.1.5cu.748_B20211015 and upgrade to the latest TOTOLINK firmware once a patched release is published (no fixed version is named in the disclosure). Until patched, block unauthenticated access to /cgi-bin/cstecgi.cgi by disabling WAN-side remote management or restricting admin access to trusted hosts, and re-verify Smart QoS settings for unexpected deletions.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (the only firmware version named in the disclosure; other builds not confirmed)
Estimated exposure
largetens of thousands of internet-exposed T6 routers (estimate) — Public internet scans (e.g., Shodan/FOFA) routinely surface on the order of 100,000+ exposed TOTOLINK routers across the vendor's model range, and the T6 is one of its widely deployed budget AC1200 models, making a five-figure exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.