← Terug naar overzicht

CVE-2026-51720 describes an incorrect access control vulnerability in the TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. The flaw exists in the delIpPortFilterRules function, which fails to enforce authentication before processing requests. Unauthenticated remote attackers can exploit this by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. Successful exploitation allows attackers to delete firewall IP/port filter rules, potentially exposing the network to further attacks. The vulnerability is significant because it undermines network perimeter defenses without requiring any credentials. It affects TOTOLINK T6 routers, which are consumer and small business networking devices. References include GitHub repositories detailing vendor coordination efforts and the TOTOLINK official website for firmware downloads.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Related CVE's

  • CVE-2026-51720

Categories

  • Mobile & IoT
  • Network Infrastructure