ZeroHour

CVE-2026-51741

niche

Unauthenticated log-erasure flaw (CWE-284) in TOTOLINK T6 router

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51741 is an incorrect access control issue (CWE-284) in the clearDiagnosisLog function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, reaching the diagnosis-log clearing routine without any credentials. The attacker gains the ability to erase the device's diagnosis logs, which destroys troubleshooting and forensic evidence on the box; the flaw carries a critical CVSS 3.1 score of 9.8. Any TOTOLINK T6 running the listed firmware is affected, especially units whose web management interface is reachable from untrusted networks such as the internet. There is currently no public proof of concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at 0.4%, so no exploitation is known at this time.

What to do: Check whether your TOTOLINK T6 runs firmware 4.1.5cu.748_B20211015 and apply a patched firmware from TOTOLINK's official support/download page when one is released (no fixed version is specified in the available data). In the meantime, restrict access to the router's web management interface and /cgi-bin/cstecgi.cgi to trusted networks only, avoiding direct internet exposure. Because the flaw allows silent log erasure, copy or forward diagnosis logs off-device if you rely on them for troubleshooting or incident investigation.

Affected
TOTOLINK T6 router firmware (clearDiagnosisLog in /cgi-bin/cstecgi.cgi)4.1.5cu.748_B20211015 (other firmware versions not specified in the available data)
Estimated exposure
nichelikely on the order of thousands to tens of thousands of devices (single consumer router model; no public install-base or internet-scan counts available) — Only the TOTOLINK T6 consumer router model is named in the data with one listed firmware build, and no public scan or active-install counts for this model are available, so the affected population is assumed to be limited to owners of this…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.