Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-51715: TOTOLINK T6 router lets anyone delete MAC filter rules

CVE-2026-51715 · published 3 days ago
Summary

The T6 router’s software does not properly verify who can change its device‑address filter list. This allows anyone on the network to send a simple request that removes those filters, letting unauthorized devices connect. Install the latest firmware from the vendor or disable the address filter if it isn’t needed.

Original advisory text
Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC filter rules via sending a crafted POST request to /cg...
Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published31 Aug 2026
Updated2 Sep 2026
First seen31 Aug 2026
Sources
CVE-2026-51715 · MITRE
Monitor software like this
Free during beta