ZeroHour

CVE-2026-51730

Unauthenticated access-control flaw lets attackers clear Wi-Fi ACL rules on TOTOLINK T6

CVSS 3.1
9.1 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-51730 is an incorrect access-control flaw (CWE-284) in the delWiFiAclRules function of TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, and the device processes the ACL-deletion command without requiring any authentication. As a result, the attacker can silently delete existing Wi-Fi ACL (access control list) rules, removing MAC-based access restrictions so that previously blocked clients can connect to the network; CVSS rates the confidentiality and integrity impact as high. Owners and administrators of TOTOLINK T6 routers running the cited firmware are affected, especially where the router's web management interface is reachable from the WAN. There is currently no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS is low (0.3%), so exploitation is not known to be occurring, but the unauthenticated network vector warrants prompt remediation.

What to do: Check your T6 firmware version and, since no fixed version is specified in the data, monitor TOTOLINK's official support/download page for an updated T6 firmware release and apply it when available. As an interim mitigation, do not expose the router's management interface (the /cgi-bin/cstecgi.cgi endpoint) to the internet — restrict web administration to the LAN and disable WAN-side management. Review the device's current Wi-Fi ACL rules for signs of unexpected or complete deletion, and re-add any access restrictions that were removed.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (the firmware version cited in the advisory; no other affected or fixed version ranges were provided)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.