Junglewise Threat Intelligence

CVE-2026-51726: TOTOLINK T6 access control bypass in delParentalRules

CVE-2026-51726 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a residential WiFi router that includes parental control features to restrict device access. An unauthenticated attacker can remove parental control rules by sending a specially crafted request to the router's web interface, effectively disabling safety protections without user knowledge or authorization.

Technical details

The vulnerability is an incorrect access control flaw in the delParentalRules function within the cstecgi.cgi endpoint. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to delete parental control rules without requiring valid authentication credentials. The router does not properly validate the request source, allowing network-based attackers to disable parental controls remotely. No patches are known to be available for the affected version 4.1.5cu.748_B20211015.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References