CVE-2026-51741
nicheUnauthenticated log-erasure flaw (CWE-284) in TOTOLINK T6 router
CVE-2026-51741 is an incorrect access control issue (CWE-284) in the clearDiagnosisLog function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, reaching the diagnosis-log clearing routine without any credentials. The attacker gains the ability to erase the device's diagnosis logs, which destroys troubleshooting and forensic evidence on the box; the flaw carries a critical CVSS 3.1 score of 9.8. Any TOTOLINK T6 running the listed firmware is affected, especially units whose web management interface is reachable from untrusted networks such as the internet. There is currently no public proof of concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at 0.4%, so no exploitation is known at this time.
What to do: Check whether your TOTOLINK T6 runs firmware 4.1.5cu.748_B20211015 and apply a patched firmware from TOTOLINK's official support/download page when one is released (no fixed version is specified in the available data). In the meantime, restrict access to the router's web management interface and /cgi-bin/cstecgi.cgi to trusted networks only, avoiding direct internet exposure. Because the flaw allows silent log erasure, copy or forward diagnosis logs off-device if you rely on them for troubleshooting or incident investigation.
| TOTOLINK T6 router firmware (clearDiagnosisLog in /cgi-bin/cstecgi.cgi) | 4.1.5cu.748_B20211015 (other firmware versions not specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.