Sceawere

Vulnerability Detail

CVE-2026-51736UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TOTOLINK T6 Unauthenticated Log Deletion

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
22h ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-31T20:17:04.877Z",
  "pubdate": "2026-08-31T20:17:04.877Z",
  "executiveSummary": "The TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 contains a critical vulnerability stemming from improper access control mechanisms within its management interface.\nThis flaw specifically affects the clearSyslog function, which is reachable through the cgi-bin/cstecgi.cgi endpoint.\nThe vulnerability allows remote, unauthenticated attackers to trigger the erasure of system logs, thereby compromising the integrity of audit trails and diagnostic data.\nThis constitutes an unauthorized administrative action performed without valid authentication credentials, posing a significant risk to forensic analysis and security monitoring capabilities.\nThe attack vector is network-accessible and requires no specific privilege level, as the application fails to validate the requester's session state before executing the log clearance operation.\nExploitation allows malicious actors to systematically destroy evidence of unauthorized activities or system compromises, severely hindering incident response and security auditing processes.",
  "technicalDetails": "The vulnerability originates from an inadequate implementation of authentication and authorization checks within the clearSyslog function, which is exposed via the /cgi-bin/cstecgi.cgi Common Gateway Interface (CGI) handler.\nIn the affected TOTOLINK T6 firmware (4.1.5cu.748_B20211015), the web server does not enforce session validation or administrative privilege verification for requests targeted at this specific function.\nThe attack flow commences with an attacker constructing a specially crafted HTTP POST request directed at the /cgi-bin/cstecgi.cgi endpoint.\nBecause the function lacks an integrated security gatekeeper, the backend process logic executes the log deletion routine immediately upon receipt of the request without checking if the sender has been previously authenticated via a session token or administrative cookie.\nThe payload behavior involves the invocation of the internal log management routines that interact directly with the device's persistent storage where syslog information is aggregated.\nBy bypassing the standard authentication lifecycle, the attacker directly manipulates the operational state of the device's logging subsystem.\nThe lack of input sanitization or context-aware access control means that any unauthenticated entity on the same network segment as the management interface can successfully execute this administrative command.\nThe post-exploitation impact is primarily the permanent destruction of system logs, which facilitates anti-forensics. By clearing the logs, an attacker can mask lateral movement, configuration changes, or the installation of secondary payloads, effectively blinding administrators to the attacker's presence and activities.\nThe root cause is identified as an authorization bypass error, where the API endpoint responsible for log maintenance fails to perform a mandatory check for a valid session object before executing sensitive system-level commands, violating the principle of least privilege in the administrative control plane."
}
CVE-2026-51736: TOTOLINK T6 Unauthenticated Log Deletion (CRITICAL Severity, CVSS: 9.1) - Sceawere