Description
Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the delVlanCfg routine of TOTOLINK T6 firmware 4.1.5cu.748_B20211015, where a missing access control check allows an attacker to send a specially crafted POST request to /cgi-bin/cstecgi.cgi and cause the router to delete existing VLAN configuration entries. The deletion is performed without authentication, meaning the attacker does not need any credentials and only requires network reachability to the router’s web management interface. This loss of VLAN entries can eliminate network isolation, allowing traffic that should be segregated to cross VLAN boundaries or trigger a denial‑of‑service by removing critical VLANs.

Affected Systems

The issue specifically affects TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No other vendor or product releases are known to be impacted, and TOTOLINK has not yet published a vendor‑specific fix. The flaw is limited to the router’s management interface exposed on the local or remote network.

Risk and Exploitability

The EPSS score for this vulnerability is not available, and it is not listed in CISA’s KEV catalog, so the measurable likelihood of exploitation remains unknown. The attack vector is inferred to be local or remote access to the router’s web‑management interface, which is common in residential or small office environments. Because the flaw removes authorization checks, an attacker who can reach the interface can potentially bypass VLAN segmentation and cause widespread network disruption. In the absence of a public exploit, the risk is considered moderate awaiting a vendor‑issued fix.

Generated by OpenCVE AI on August 31, 2026 at 20:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware upgrade from TOTOLINK that resolves the delVlanCfg access‑control flaw.
  • If an update is unavailable, block external access to the router’s web‑management interface or confine it to the internal network to prevent unauthenticated POST requests.
  • Consider disabling remote web management entirely if it is not required.
  • Monitor router logs for unexpected POST activity to /cgi-bin/cstecgi.cgi and investigate any anomalies promptly.

Generated by OpenCVE AI on August 31, 2026 at 20:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated VLAN Deletion via delVlanCfg Function
Weaknesses CWE-284

Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T19:03:07.499Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51731

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-31T20:17:04.353

Modified: 2026-08-31T20:59:32.817

Link: CVE-2026-51731

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T21:00:05Z

Weaknesses