ZeroHour

CVE-2026-51729

niche

Unauthenticated device deletion flaw in TOTOLINK T6 mesh Wi-Fi system

CVSS 3.1
9.1 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an incorrect access control issue (CWE-284) in the delDevice function of its web management CGI. An unauthenticated attacker can trigger the flaw by sending a crafted POST request to /cgi-bin/cstecgi.cgi, without needing credentials or user interaction. Successful exploitation lets the attacker request deletion of a managed slave device, i.e., a mesh satellite unit managed by the T6, which can remove extension nodes from the wireless network and disrupt the mesh; the flaw carries a critical CVSS 3.1 score of 9.1. Anyone running the affected T6 firmware is exposed, particularly units whose management interface is reachable from the WAN. No public proof-of-concept is known, the CVE is not in CISA KEV, and EPSS puts 30-day exploitation probability at about 0.3%, so exploitation is not currently observed.

What to do: Check whether your T6 runs firmware 4.1.5cu.748_B20211015 and apply a patched firmware from TOTOLINK when one is released (no fixed version is specified in the available data). Until then, restrict exposure of the router's management interface — do not forward or expose /cgi-bin/cstecgi.cgi to the WAN — and monitor for unauthenticated POST requests targeting that endpoint.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (firmware version referenced in the advisory; no broader fixed or affected range provided)
Estimated exposure
nichelikely on the order of thousands of exposed units (exact install base for the T6 model unknown) — No install-base or scan data is provided for the T6; the estimate relies on deployment patterns — it is a single consumer mesh model from TOTOLINK, whose internet-exposed device counts in public scans are in the tens of thousands across…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to request deletion of a managed slave device via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.