CVE-2026-51730
—Unauthenticated access-control flaw lets attackers clear Wi-Fi ACL rules on TOTOLINK T6
CVE-2026-51730 is an incorrect access-control flaw (CWE-284) in the delWiFiAclRules function of TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, and the device processes the ACL-deletion command without requiring any authentication. As a result, the attacker can silently delete existing Wi-Fi ACL (access control list) rules, removing MAC-based access restrictions so that previously blocked clients can connect to the network; CVSS rates the confidentiality and integrity impact as high. Owners and administrators of TOTOLINK T6 routers running the cited firmware are affected, especially where the router's web management interface is reachable from the WAN. There is currently no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS is low (0.3%), so exploitation is not known to be occurring, but the unauthenticated network vector warrants prompt remediation.
What to do: Check your T6 firmware version and, since no fixed version is specified in the data, monitor TOTOLINK's official support/download page for an updated T6 firmware release and apply it when available. As an interim mitigation, do not expose the router's management interface (the /cgi-bin/cstecgi.cgi endpoint) to the internet — restrict web administration to the LAN and disable WAN-side management. Review the device's current Wi-Fi ACL rules for signs of unexpected or complete deletion, and re-add any access restrictions that were removed.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (the firmware version cited in the advisory; no other affected or fixed version ranges were provided) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.