Junglewise Threat Intelligence

CVE-2026-51729: TOTOLINK T6 unauthenticated device deletion in delDevice

CVE-2026-51729 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

The TOTOLINK T6 mesh router allows attackers without credentials to delete managed slave devices in the network by sending a crafted request. An attacker could disrupt network operations by removing devices, preventing users from extending their Wi-Fi coverage and forcing network reconfiguration.

Technical details

The delDevice function in the cstecgi.cgi CGI script lacks proper authentication checks, allowing unauthenticated POST requests to delete managed slave devices from the mesh network. An attacker on the network or with access to the router's web interface can exploit this by sending a crafted POST request to /cgi-bin/cstecgi.cgi without providing valid credentials. This results in unauthorized removal of slave devices from the mesh topology, disrupting network connectivity and availability. No patch information is currently available.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed
  • other: Reported as CVE-2026-51729

References