Access Control Vulnerability in TOTOLINK Router Firmware
CVE-2026-51741

9.8CRITICAL

Key Information:

Vendor

TOTOLINK

Vendor
CVE Published:
1 September 2026

What is CVE-2026-51741?

A vulnerability exists in the TOTOLINK T6 router firmware that allows unauthorized users to manipulate sensitive functionality. Specifically, the clearDiagnosisLog function is improperly secured, permitting unauthenticated attackers to delete diagnosis logs by sending tailored POST requests to the endpoint /cgi-bin/cstecgi.cgi. This weakness can lead to potential information exposure, as critical log information can be erased without authentication, compromising system integrity.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.