ZeroHour

CVE-2026-51726

niche

Unauthenticated parental-control rule deletion in TOTOLINK T6 router firmware

CVSS 3.1
9.1 critical
EPSS
<1%p30
Published
()
Modified
AI analysis

TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015 contains an incorrect access control flaw (CWE-284) in the delParentalRules function of its web management interface. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to delete the device's parental-control rules without any credentials or user interaction. Successful exploitation lets an attacker silently strip parental-control and content-filtering settings from the router, and the critical 9.1 CVSS score (AV:N/AC:L/PR:N/UI:N with high confidentiality and integrity impact) reflects that the endpoint accepts network-reachable, unauthenticated requests. Affected are TOTOLINK T6 routers running the named firmware build, whether targeted from the local network or remotely if the management interface is exposed to the internet (e.g., via remote management or port forwarding). There is no known public proof-of-concept, the CVE is not in CISA KEV, and the 0.4% EPSS score indicates no confirmed exploitation activity at this time.

What to do: Check the TOTOLINK support site for a firmware release newer than 4.1.5cu.748_B20211015 for the T6 and update when available, since no fixed version is named in the current data. In the meantime, disable WAN-side remote management or restrict access to /cgi-bin/cstecgi.cgi to trusted hosts, and review the router's parental-control rule list for unexpected deletions.

Affected
TOTOLINK T6 routerfirmware 4.1.5cu.748_B20211015 (the only version named in the advisory; whether other builds are affected is not stated in the data)
Estimated exposure
nichelikely hundreds to low thousands of internet-exposed TOTOLINK T6 units (subset of the tens of thousands of TOTOLINK routers visible in public internet scans);… — TOTOLINK is a budget consumer/SOHO router brand whose management interfaces routinely appear internet-exposed in public scan data, but no public scan count exists for the T6 model specifically, so this is an order-of-magnitude estimate…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.