← Back to overview

CVE-2026-51720 describes an incorrect access control vulnerability in the delIpPortFilterRules function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to delete firewall filter rules by sending a specially crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. No authentication is required to exploit this vulnerability, making it particularly dangerous as attackers can silently weaken the device's firewall posture. Successful exploitation could expose the network to further attacks by removing protective filtering rules. The vulnerability was reported via GitHub-hosted CVE vendor coordination repositories and affects TOTOLINK networking hardware. This type of unauthenticated access control bypass in network infrastructure devices poses significant risk to home and small business users.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Related CVE's

  • CVE-2026-51720

IOC's

/cgi-bin/cstecgi.cgi

Categories

  • Mobile & IoT
  • Network Infrastructure