CVE-2026-51726
nicheUnauthenticated parental-control rule deletion in TOTOLINK T6 router firmware
TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015 contains an incorrect access control flaw (CWE-284) in the delParentalRules function of its web management interface. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to delete the device's parental-control rules without any credentials or user interaction. Successful exploitation lets an attacker silently strip parental-control and content-filtering settings from the router, and the critical 9.1 CVSS score (AV:N/AC:L/PR:N/UI:N with high confidentiality and integrity impact) reflects that the endpoint accepts network-reachable, unauthenticated requests. Affected are TOTOLINK T6 routers running the named firmware build, whether targeted from the local network or remotely if the management interface is exposed to the internet (e.g., via remote management or port forwarding). There is no known public proof-of-concept, the CVE is not in CISA KEV, and the 0.4% EPSS score indicates no confirmed exploitation activity at this time.
What to do: Check the TOTOLINK support site for a firmware release newer than 4.1.5cu.748_B20211015 for the T6 and update when available, since no fixed version is named in the current data. In the meantime, disable WAN-side remote management or restrict access to /cgi-bin/cstecgi.cgi to trusted hosts, and review the router's parental-control rule list for unexpected deletions.
| TOTOLINK T6 router | firmware 4.1.5cu.748_B20211015 (the only version named in the advisory; whether other builds are affected is not stated in the data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.