Junglewise Threat Intelligence

CVE-2026-51719: TOTOLINK T6 incorrect access control in URL filtering

CVE-2026-51719 · Severity: high · CVSS 7.5 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a wireless router used to provide internet connectivity in homes and small offices. An attacker on the network can send a specially crafted request to disable the router's URL filtering security feature without providing any password or authentication, allowing blocked websites to be accessed and potentially bypassing parental controls or corporate security policies.

Technical details

The vulnerability exists in the delUrlFilterRules function of the cstecgi.cgi CGI application running on the TOTOLINK T6 router. The function fails to verify the attacker's identity before processing requests to delete URL filtering rules. An unauthenticated attacker with network access to the router can send a crafted POST request to /cgi-bin/cstecgi.cgi to remove URL filtering rules, effectively disabling this security feature. No authentication credentials or special privileges are required to exploit this flaw. A patch or firmware update is not yet publicly available.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References