Sceawere

Vulnerability Detail

CVE-2026-51726UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TOTOLINK T6 Parental Rule Bypass

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
1d ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-31T18:17:18.320Z",
  "pubdate": "2026-08-31T18:17:18.320Z",
  "executiveSummary": "The TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 contains an improper access control vulnerability within its parental control management interface.\nThis vulnerability allows unauthenticated, remote attackers to manipulate or delete existing parental-control rules without requiring administrative credentials.\nThe flaw originates from insufficient verification of user identity during the invocation of the delParentalRules function via the CGI interface.\nSuccessful exploitation permits an attacker to bypass established security restrictions, potentially exposing users or restricted devices to content or services that were intentionally blocked by administrative policy.\nThis poses a significant risk to network security, particularly in environments where parental filtering is relied upon to enforce safety or compliance policies.\nExploitation requires no prior authentication and can be achieved through a crafted network request, making the device susceptible to external interference.",
  "technicalDetails": "The vulnerability resides within the cgi-bin/cstecgi.cgi binary, specifically impacting the logic governing the delParentalRules function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015.\nThe root cause is an insecure implementation of access control mechanisms where the system fails to validate the session state or authorization token of the requester before processing administrative commands.\nWhen a user or attacker sends a specifically crafted HTTP POST request to the /cgi-bin/cstecgi.cgi endpoint, the application incorrectly trusts the input parameters intended to manage parental-control rules.\nThe attack flow proceeds as follows: First, the attacker identifies the /cgi-bin/cstecgi.cgi URI as the gateway for system management tasks. Second, the attacker crafts a POST request that triggers the delParentalRules function. Third, because the function does not perform a robust check for a valid session cookie or an authenticated administrative context, the backend CGI handler processes the request with elevated privileges.\nThe lack of server-side authentication allows the payload to successfully execute the removal of existing parental control rule entries from the system's underlying configuration storage.\nThe scope of impact is limited to the functionality controlled by the affected function; however, the ability to modify security policies without authorization represents a complete breakdown of the device's access control enforcement.\nThe vulnerability is accessible over the network, assuming the interface is exposed to the local network or internet. Given that the web interface handles sensitive administrative operations, the absence of per-request authentication is a critical security oversight in the firmware's design.\nPost-exploitation, an attacker can effectively disable any restrictions previously set by the network administrator, leading to an unauthorized modification of the device's security posture and potentially enabling access to unauthorized or restricted network segments or content."
}
CVE-2026-51726: TOTOLINK T6 Parental Rule Bypass (CRITICAL Severity, CVSS: 9.1) - Sceawere