Junglewise Threat Intelligence

CVE-2026-51716: TOTOLINK T6 unauthorized port-forwarding rule deletion

CVE-2026-51716 · Severity: high · CVSS 7.5 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a home/small-office router that manages network traffic and port forwarding. This vulnerability allows unauthenticated attackers to delete port-forwarding rules via the web interface, disrupting legitimate network traffic routing and potentially exposing the network to intrusion by eliminating security controls.

Technical details

The vulnerability is an improper access control flaw in the delPortForwardRules function of cstecgi.cgi, a web administration interface on TOTOLINK T6. Affected versions prior to 4.1.5cu.748_B20211015 do not properly authenticate requests before processing port-forwarding rule deletion. An unauthenticated attacker on the network can craft a POST request to /cgi-bin/cstecgi.cgi and delete port-forwarding rules without credentials, resulting in service disruption and potential network misconfiguration. The attack requires network access but no user interaction or authentication.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015 and earlier

Timeline

  • 2026-08-31: disclosed

References