Sceawere

Vulnerability Detail

CVE-2026-51730UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TOTOLINK T6 ACL Bypass Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
14h ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-31T18:17:18.770Z",
  "pubdate": "2026-08-31T18:17:18.770Z",
  "executiveSummary": "This vulnerability concerns an improper access control flaw identified within the TOTOLINK T6 firmware version 4.1.5cu.748_B20211015.\nThe vulnerability resides in the 'delWiFiAclRules' function, which fails to adequately validate the authentication state of incoming requests.\nUnauthenticated remote attackers can exploit this flaw to modify or delete existing Wi-Fi Access Control List (ACL) rules on the affected device.\nSuccessful exploitation allows unauthorized manipulation of network security policies, potentially enabling unauthorized devices to gain access to the Wi-Fi network by removing restrictions.\nThe vulnerability is accessible via the network, specifically through the 'cgi-bin/cstecgi.cgi' endpoint.\nGiven that the vulnerability does not require authentication, the risk level is elevated, as any attacker with network access to the device can perform these modifications.",
  "technicalDetails": "The vulnerability is rooted in an authentication bypass mechanism within the 'delWiFiAclRules' function of the TOTOLINK T6 firmware (4.1.5cu.748_B20211015).\nIn the device's web management interface, the CGI script '/cgi-bin/cstecgi.cgi' serves as the entry point for executing administrative commands. The 'delWiFiAclRules' function, responsible for managing the removal of Wi-Fi Access Control List (ACL) entries, lacks the necessary security checks to verify that the requester is a legitimately authenticated administrator.\nAttackers can leverage this by sending a crafted HTTP POST request directed at the '/cgi-bin/cstecgi.cgi' endpoint. By constructing a payload that invokes the 'delWiFiAclRules' function, an unauthenticated actor can manipulate the device's ACL configuration without satisfying the administrative authentication requirements usually mandated for such sensitive actions.\nThe attack flow follows a direct request pattern: 1) The attacker constructs a malicious HTTP POST request targeting the CGI handler. 2) The handler parses the request and routes the execution to 'delWiFiAclRules'. 3) Due to the absence of a proper session validation check, the function executes the removal logic with the permissions of the web service process.\nThe post-exploitation impact includes the systematic removal of white-listed or black-listed MAC addresses defined in the Wi-Fi ACL settings. This effectively neutralizes existing security controls intended to limit network access based on hardware identifiers. By removing these rules, an attacker can bypass device-level restrictions, thereby allowing unauthorized clients to associate with the Wi-Fi network that would otherwise be rejected. This exploitation is performed over the network, making it a significant concern for devices exposed to untrusted environments.\nThe vulnerability underscores a critical failure in the application's authorization layer, as internal administrative functions are exposed without prerequisite authentication validation within the CGI execution environment."
}
CVE-2026-51730: TOTOLINK T6 ACL Bypass Vulnerability (CRITICAL Severity, CVSS: 9.1) - Sceawere