Sceawere

Vulnerability Detail

CVE-2026-51729UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TOTOLINK T6 Unauthenticated Device Deletion

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
1d ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to request deletion of a managed slave device via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-31T18:17:18.653Z",
  "pubdate": "2026-08-31T18:17:18.653Z",
  "executiveSummary": "The TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 contains an improper access control vulnerability within the delDevice function.\nThis vulnerability allows unauthenticated, remote attackers to trigger the deletion of managed slave devices by submitting specifically crafted POST requests to the cgi-bin/cstecgi.cgi endpoint.\nThe flaw stems from a lack of session validation or authentication checks prior to executing administrative commands within the device management interface.\nImpact includes the unauthorized removal of network devices, potentially resulting in Denial of Service (DoS) for the affected sub-networks or legitimate management infrastructure.\nThe vulnerability poses a significant risk to network integrity and device availability, as it requires no prior credentials for successful exploitation.\nThe attack vector is network-based, meaning the vulnerability is exploitable by any actor capable of reaching the device's management interface.",
  "technicalDetails": "The vulnerability resides within the delDevice function, which is responsible for handling the removal of slave devices in a mesh or managed network environment within the TOTOLINK T6 product line.\nThe root cause of the vulnerability is the absence of server-side authentication verification in the cgi-bin/cstecgi.cgi handler. The application fails to validate the requester's session token or authorization level before invoking the underlying logic that processes device management requests.\nExploitation is achieved by transmitting a crafted POST request to the /cgi-bin/cstecgi.cgi URI. The request must include parameters that invoke the delDevice function, effectively bypassing the security controls that would otherwise restrict this operation to authenticated administrators.\nThe attack flow follows a direct exploitation pattern: First, the attacker identifies the target TOTOLINK T6 device on the network. Second, the attacker constructs an HTTP POST request targeting /cgi-bin/cstecgi.cgi. This payload includes the necessary function call (delDevice) and the required arguments (typically the device identifier or MAC address of the slave device intended for removal). Finally, the server processes the request as a trusted command without checking if the initiator has established an authorized session.\nBecause the system trusts the incoming POST request inherently, the back-end routine invokes the system calls required to unregister the specified device from the master unit’s configuration database. This effectively deletes the device configuration, removes it from the mesh network, and forces a re-provisioning or a loss of connectivity for the slave device.\nThe vulnerability affects TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. Since the vulnerability is triggered via the CGI interface, any network segment that can communicate with the device's administrative web interface can facilitate the attack. No privileges are required, and the exploitation is entirely unauthenticated, allowing any attacker with network access to the management endpoint to cause persistent disruption to the network topology."
}
CVE-2026-51729: TOTOLINK T6 Unauthenticated Device Deletion (CRITICAL Severity, CVSS: 9.1) - Sceawere