Junglewise Threat Intelligence

CVE-2026-51730: TOTOLINK T6 access control bypass in delWiFiAclRules

CVE-2026-51730 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a wireless router used in homes and small businesses to provide Wi-Fi network access. The device's Wi-Fi access control list (ACL) feature, which manages which devices can connect to the network, can be disabled by unauthenticated attackers sending a crafted request to the device's web interface. This allows anyone with network access to compromise network security by removing access restrictions and allowing unauthorized devices to join.

Technical details

The vulnerability is an authentication bypass and improper access control in the delWiFiAclRules function of the cstecgi.cgi web application on TOTOLINK T6. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi to invoke this function without providing valid credentials. The attack is network-reachable and requires no user interaction. An attacker can delete Wi-Fi ACL rules, removing network access restrictions and allowing unauthorized devices to connect to the wireless network. The vulnerability affects firmware version 4.1.5cu.748_B20211015 and likely other versions.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References