Description
Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect access control in the delMacFilterRules function of TOTOLINK T6 allows an unauthenticated attacker to remove MAC filter rules by sending a crafted POST request to /cgi-bin/cstecgi.cgi. This deletion disables the enforced device whitelist, enabling any device to connect to the network without authorization and potentially compromise network resources.

Affected Systems

The vulnerability affects TOTOLINK T6 running firmware version 4.1.5cu.748_B20211015. Only this specific build contains the flaw, so check if your device uses that firmware and consider upgrading to a version that removes the error.

Risk and Exploitability

The flaw can be exploited remotely by any party that can reach the router’s HTTP interface and submit a POST request, as no authentication is required. The exploitation requires only the ability to send HTTP traffic to the target and is not dependent on privileged credentials. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, but the impact of completely disabling MAC address filtering poses a high risk to network security and integrity.

Generated by OpenCVE AI on August 31, 2026 at 17:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router firmware to a version that contains the access control fix
  • If no newer firmware is available, disable remote access to /cgi-bin/cstecgi.cgi through a firewall or router ACL to block unauthenticated POST requests
  • After disabling the vulnerability, re‑apply MAC filter rules and verify that the list cannot be cleared without authentication

Generated by OpenCVE AI on August 31, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Deletion of MAC Filter Rules in TOTOLINK T6
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T15:56:12.064Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51715

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T16:18:36.647

Modified: 2026-08-31T16:18:36.647

Link: CVE-2026-51715

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T17:30:03Z

Weaknesses