Description
Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-09-01
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Log Deletion
Action: Apply Update
AI Analysis

Impact

The vulnerability resides in the clearDiagnosisLog function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and remove all stored diagnostics logs. This loss of evidence can hinder troubleshooting, obscure fault causes, and facilitate the concealment of malicious activity, but it does not provide direct code execution or broader system compromise. The flaw is a classic case of incorrect access control, which permits privileged actions to be performed by anyone with network access to the device.

Affected Systems

The affected product is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other vendors or product lines are listed as impacted in the current advisory.

Risk and Exploitability

EPSS score is < 1% and the vulnerability is not listed in CISA KEV. The CVSS score is 9.8, indicating a critical severity despite the limited impact of log deletion. Unauthenticated attackers can exploit the flaw by crafting a POST request to the CGI endpoint from any machine that can reach the router’s local network. No authentication or privileged credentials are required, making exploitation straightforward for network inside actors.

Generated by OpenCVE AI on September 3, 2026 at 20:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to a version where the clearDiagnosisLog access control has been fixed
  • Restrict or block access to /cgi-bin/cstecgi.cgi through firewall rules or network segmentation to prevent unauthenticated POST requests
  • Configure intrusion detection or logging to alert on POST attempts to the clearDiagnosisLog endpoint

Generated by OpenCVE AI on September 3, 2026 at 20:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Log Deletion via Incorrect Access Control in TOTOLINK T6 4.1.5cu.748_B20211015

Thu, 03 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Log Deletion via Incorrect Access Control in TOTOLINK T6 4.1.5cu.748_B20211015
Weaknesses CWE-284

Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6

Tue, 01 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-03T17:25:10.848Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51741

cve-icon Vulnrichment

Updated: 2026-09-03T15:00:28.593Z

cve-icon NVD

Status : Deferred

Published: 2026-09-01T13:19:45.047

Modified: 2026-09-03T18:17:21.747

Link: CVE-2026-51741

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T21:00:12Z

Weaknesses