Description
Incorrect access control in the delPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to delete port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from an access control flaw in the delPortForwardRules function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. Unauthenticated attackers can craft a POST request to /cgi-bin/cstecgi.cgi, causing incorrect permission checks to delete port-forwarding rules. This deletion can disrupt network traffic routing, potentially disabling forwarded services or redirecting traffic. The flaw is a classic example of missing authentication or authorization checks, compounding the risk for network administrators. The impact is limited to the scope of port-forwarding configuration; it does not grant full administrative access.

Affected Systems

The affected environment includes TOTOLINK T6 routers that are running the disclosed firmware version 4.1.5cu.748_B20211015. No additional vendor or product versions are explicitly enumerated in the CVE data. Administrators of any installations using this firmware should verify whether the router runs the stated firmware revision.

Risk and Exploitability

The CVSS score is not provided in the data, and the EPSS score is unavailable, meaning the likelihood of exploitation cannot be quantified. However, because the vulnerability requires only a crafted HTTP POST and provides no authentication, if an attacker can reach the router externally or via an internal network, the delete operation can be performed with ease. Since the issue is not listed in the CISA KEV catalog, there is no evidence of active exploitation, but the potential for accidental misconfiguration or malicious deletion remains. The lack of a proven exploit does not diminish the need for remediation, given the disruptive effect on port forwarding, which is a critical configuration for many home and small‑business networks.

Generated by OpenCVE AI on August 31, 2026 at 17:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router firmware to a version that removes the flaw as released by TOTOLINK
  • If an immediate upgrade is not possible, restrict external access to the /cgi-bin/cstecgi.cgi endpoint, for example by blocking the router’s management port to untrusted networks
  • Continuously monitor the port-forwarding configuration for unauthorized changes and audit logs for anomalous POST requests

Generated by OpenCVE AI on August 31, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Port-Forwarding Rule Deletion in TOTOLINK T6
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the delPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to delete port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T15:56:37.874Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51716

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T16:18:36.760

Modified: 2026-08-31T16:18:36.760

Link: CVE-2026-51716

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T17:30:03Z

Weaknesses