Sceawere

Vulnerability Detail

CVE-2026-51724UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TOTOLINK T6 Incorrect Access Control

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
1d ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-31T17:17:41.950Z",
  "pubdate": "2026-08-31T17:17:41.950Z",
  "executiveSummary": "The TOTOLINK T6 router (version 4.1.5cu.748_B20211015) contains an incorrect access control vulnerability within its web management interface.\nThe vulnerability resides in the delSmartQosCfg function, which fails to enforce proper authentication checks before executing administrative operations.\nAn unauthenticated, remote attacker can leverage this flaw to arbitrarily remove Smart QoS rules by submitting a specifically crafted POST request to the /cgi-bin/cstecgi.cgi endpoint.\nThe lack of session validation or authorization checks enables unauthorized configuration manipulation, which could lead to service degradation, traffic prioritization bypass, or potential denial-of-service conditions regarding network management.\nThis vulnerability poses a significant risk to the integrity and availability of the device's network traffic management capabilities, as it does not require prior knowledge of legitimate user credentials.\nExploitation is straightforward and does not require elevated privileges, making it accessible to any actor with network access to the device's management interface.",
  "technicalDetails": "The vulnerability is localized within the delSmartQosCfg function, which is responsible for handling the deletion of Quality of Service (QoS) configurations in the TOTOLINK T6 firmware version 4.1.5cu.748_B20211015.\nThe root cause of this vulnerability is an improper access control implementation within the CGI (Common Gateway Interface) handler. The application fails to verify the session state or the authentication status of the requester before processing the command to modify the QoS rule set.\nThe attack vector involves sending an unauthorized HTTP POST request to the /cgi-bin/cstecgi.cgi resource. This URI serves as the main gateway for the device's internal configuration management. When the request reaches the server, the underlying binary associated with the CGI interface fails to perform a mandatory check for a valid session token or administrative privilege.\nThe exploit flow consists of the attacker crafting a POST payload that triggers the internal delSmartQosCfg function. Because the function logic lacks a guard clause to validate the caller's identity, it directly processes the request body to identify and remove existing QoS configuration entries from the device's non-volatile memory.\nThe impact of this vulnerability is the unauthorized removal of network traffic shaping rules. By deleting these rules, an attacker can effectively disable the Smart QoS mechanism, resulting in an inability to prioritize critical traffic, potentially causing network congestion or performance degradation for legitimate users relying on those rules.\nThe vulnerability is characterized by a lack of authentication requirements, meaning the device does not differentiate between a legitimate administrator and an unauthenticated network participant. Since the /cgi-bin/cstecgi.cgi interface is typically reachable via the local area network, and often exposed to the WAN depending on the user's firewall configuration, the attack surface is significant.\nSuccessful exploitation allows an attacker to manipulate the router's internal state without any interaction from a legitimate user. The payload behavior is strictly destructive, targeting the QoS configuration table. Post-exploitation, the device's performance characteristics change, and the attacker may use this as a preliminary step in a broader campaign to degrade network reliability or evade traffic monitoring/policing policies configured on the device."
}
CVE-2026-51724: TOTOLINK T6 Incorrect Access Control (CRITICAL Severity, CVSS: 9.8) - Sceawere