Junglewise Threat Intelligence

CVE-2026-51720: TOTOLINK T6 firewall filter rule deletion via missing authentication

CVE-2026-51720 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a home/small office router that manages network firewall rules to protect connected devices and control traffic. An unauthenticated attacker on the network can send a crafted request to completely remove firewall filter rules, disabling the device's ability to filter or block malicious traffic and exposing the network to unauthorized access and attacks.

Technical details

The vulnerability is an authentication bypass (incorrect access control) in the delIpPortFilterRules function within cstecgi.cgi of TOTOLINK T6 version 4.1.5cu.748_B20211015. An attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to invoke this function without providing valid credentials. The function fails to validate the caller's authentication status before processing the request, allowing an unauthenticated, network-adjacent attacker to delete firewall filter rules. This results in complete loss of firewall protection on that rule set. No patch status is known at this time.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References