ZeroHour

CVE-2026-51731

moderate

Unauthenticated access-control flaw in TOTOLINK T6 allows VLAN deletion

CVSS 3.1
9.1 critical
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51731 is an improper access-control issue (CWE-284) in the delVlanCfg function of the TOTOLINK T6 router, confirmed on firmware version 4.1.5cu.748_B20211015. An unauthenticated remote attacker can trigger the flaw by sending a crafted POST request to /cgi-bin/cstecgi.cgi, the router's web management API, invoking delVlanCfg without any authentication. Successful exploitation allows the attacker to remove VLAN entries from the device's configuration, which can break intended network segmentation and cause integrity and availability impacts on the affected network; the flaw is rated 9.1 (Critical) under CVSS 3.1. Administrators of TOTOLINK T6 routers running the referenced firmware are affected, with risk concentrated on units whose web management interface is reachable from the WAN or by an attacker on the local network. As of publication there is no public proof-of-concept, the flaw is not listed in CISA's KEV, and EPSS puts 30-day exploitation probability at 0.4%, so no active exploitation is known.

What to do: Check whether TOTOLINK T6 units you manage run firmware 4.1.5cu.748_B20211015 and whether the web management interface (cstecgi.cgi) is exposed to the WAN; restrict or disable remote management and firewall the admin interface, since reachability is required for exploitation. No fixed version is specified in the available data, so monitor TOTOLINK's official support channels for an updated firmware release. An interim mitigation is to ensure the router's management CGI is only reachable from trusted LAN segments.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (version cited in the advisory; full affected range not specified)
Estimated exposure
moderatelikely thousands of internet-exposed TOTOLINK devices; T6-specific counts unpublished — TOTOLINK is a widely distributed budget router brand whose devices appear in public internet scans in the tens of thousands across all models, but no published install-base or exposed-device count exists for the T6 model specifically, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.