Access Control Vulnerability in TOTOLINK Router Firmware
CVE-2026-51741
9.8CRITICAL
What is CVE-2026-51741?
A vulnerability exists in the TOTOLINK T6 router firmware that allows unauthorized users to manipulate sensitive functionality. Specifically, the clearDiagnosisLog function is improperly secured, permitting unauthenticated attackers to delete diagnosis logs by sending tailored POST requests to the endpoint /cgi-bin/cstecgi.cgi. This weakness can lead to potential information exposure, as critical log information can be erased without authentication, compromising system integrity.
