CVE-2026-51736
moderateUnauthenticated log-erasure flaw in TOTOLINK T6 router
CVE-2026-51736 is an incorrect access-control flaw (CWE-284) in the clearSyslog function of the TOTOLINK T6 router's web management interface, in firmware version 4.1.5cu.748_B20211015. An unauthenticated remote attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to invoke clearSyslog and erase the device's system logs, with no credentials or user interaction required. The attacker's gain is deletion of the router's logging history, which can conceal prior malicious activity and hamper incident response and forensics; the flaw is scored 9.1 (critical) with a network attack vector, though the described impact is integrity loss (log wipe) rather than code execution. Only TOTOLINK T6 units running the firmware cited in the advisory (4.1.5cu.748_B20211015) are confirmed affected; the full range of affected versions is not specified. There is no known public proof-of-concept, no CISA KEV listing, and no confirmed in-the-wild exploitation; EPSS assigns a 0.4% probability of exploitation within 30 days.
What to do: Check the T6 firmware version in the admin interface and apply a fixed release when TOTOLINK publishes one (no fixed version is given in the available data). Until then, do not expose the router's web management interface to the WAN (disable or restrict remote management) and consider forwarding logs to an external syslog server so they survive a wipe. Monitor for unauthenticated POST requests to /cgi-bin/cstecgi.cgi invoking clearSyslog as an indicator of probing or exploitation.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 (version confirmed in the advisory; no broader affected range or fixed version specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.