Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-51724: TOTOLINK T6 router lets anyone delete QoS rules

CVE-2026-51724 · published 3 days ago
Summary

The TOTOLINK T6 device running version 4.1.5 allows anyone on the network to send a special request that erases its Smart QoS (traffic‑priority) settings without logging in. This could cause important applications to lose priority and slow down. Update the router to the latest firmware or apply the vendor’s security patch and limit remote access to the management interface.

Original advisory text
Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafted POST request to /cgi-bi...
Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published31 Aug 2026
Updated2 Sep 2026
First seen31 Aug 2026
Sources
CVE-2026-51724 · MITRE
Monitor software like this
Free during beta