Junglewise Threat Intelligence

CVE-2026-51715: TOTOLINK T6 incorrect access control in delMacFilterRules

CVE-2026-51715 · Severity: critical · CVSS 9.8 · Published 2026-08-31

Executive brief

The TOTOLINK T6 is a wireless router used to manage network connectivity and security settings. A vulnerability in the router's web interface allows unauthenticated attackers to remove MAC address filtering rules, which could allow unauthorized devices to bypass network access controls and connect to the router's network.

Technical details

This vulnerability is an incorrect access control flaw in the delMacFilterRules function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to delete MAC filter rules without authentication. MAC filtering is a security mechanism that restricts network access to devices with approved MAC addresses; removal of these rules allows any device to connect to the network. The vulnerability requires only network access to the router's web interface—no authentication or user interaction is needed. A patch or firmware update from TOTOLINK is the recommended remediation.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References