Junglewise Threat Intelligence

CVE-2026-51731: TOTOLINK T6 incorrect access control in delVlanCfg

CVE-2026-51731 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a network router that manages virtual local area networks (VLANs) to segment network traffic. An unauthenticated attacker can remotely send a specially crafted web request to remove VLAN configurations, disrupting network segmentation and potentially isolating critical devices or exposing sensitive traffic.

Technical details

The vulnerability is an incorrect access control flaw in the delVlanCfg function of the cstecgi.cgi web interface in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The affected function fails to properly verify user authentication before processing VLAN deletion requests. An unauthenticated attacker can send a POST request to /cgi-bin/cstecgi.cgi with crafted parameters to invoke delVlanCfg and remove VLAN configurations without authentication. No precondition beyond network reachability to the router's web interface is required. Successful exploitation allows an attacker to delete VLAN entries, disrupting network segmentation and availability. A patch status is not specified in available information.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References