CVE-2026-51731
moderateUnauthenticated access-control flaw in TOTOLINK T6 allows VLAN deletion
CVE-2026-51731 is an improper access-control issue (CWE-284) in the delVlanCfg function of the TOTOLINK T6 router, confirmed on firmware version 4.1.5cu.748_B20211015. An unauthenticated remote attacker can trigger the flaw by sending a crafted POST request to /cgi-bin/cstecgi.cgi, the router's web management API, invoking delVlanCfg without any authentication. Successful exploitation allows the attacker to remove VLAN entries from the device's configuration, which can break intended network segmentation and cause integrity and availability impacts on the affected network; the flaw is rated 9.1 (Critical) under CVSS 3.1. Administrators of TOTOLINK T6 routers running the referenced firmware are affected, with risk concentrated on units whose web management interface is reachable from the WAN or by an attacker on the local network. As of publication there is no public proof-of-concept, the flaw is not listed in CISA's KEV, and EPSS puts 30-day exploitation probability at 0.4%, so no active exploitation is known.
What to do: Check whether TOTOLINK T6 units you manage run firmware 4.1.5cu.748_B20211015 and whether the web management interface (cstecgi.cgi) is exposed to the WAN; restrict or disable remote management and firewall the admin interface, since reachability is required for exploitation. No fixed version is specified in the available data, so monitor TOTOLINK's official support channels for an updated firmware release. An interim mitigation is to ensure the router's management CGI is only reachable from trusted LAN segments.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (version cited in the advisory; full affected range not specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.