A critical incorrect access control vulnerability exists in the delWiFiAclRules function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to delete Wi-Fi ACL (Access Control List) rules by sending a specially crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. No authentication or credentials are required to exploit this vulnerability. Successful exploitation could allow attackers to bypass network access controls enforced via Wi-Fi ACL rules, potentially enabling unauthorized devices to connect to protected networks. The vulnerability has been documented and coordinated through GitHub repositories linked to CVE vendor coordination efforts. TOTOLINK has been notified and firmware download references are available on their official website.