External risk intelligence

TOTOLINK T6 Router Unauthenticated MAC Filter Rule Removal

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51715

The vulnerability exists in a home networking router product. These devices are designed to be internet-facing by default, acting as the gateway between a local network and the internet, and the affected management interface is reachable via a standard web request.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability relates to a security flaw in TOTOLINK routers that could allow unauthorized access to remove network access controls. While the direct business impact is not detailed, the nature of the flaw means it's important to confirm if these devices are in use and exposed to potential threats.

  • Attackers can bypass network filters.
  • It affects internet-facing home networking equipment.
  • Confirm if this router is in your environment.

Attack Path

How an attacker could exploit the issue

An attacker can begin by sending a specially crafted POST request over the internet to the router's management interface. Because this function lacks proper access controls, the attacker does not need to log in. The request targets the `delMacFilterRules` function, which can then be used to delete MAC filter rules.

  • No authentication required.
  • Triggered via crafted POST request.
  • Removes critical network security rules.

Live Threat

Current exploitation, exposure, and threat context

Attackers can remove MAC filter rules on TOTOLINK routers, potentially impacting network access control when supported by the advisory.

  • MAC filter rules are at risk.
  • Remote attackers can send crafted requests.
  • Network access control may be bypassed.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects TOTOLINK routers, and the primary responsibility for addressing it likely lies with the network infrastructure or platform teams managing these devices. The first practical step is to identify all deployed TOTOLINK T6 routers, determine their internet exposure, and confirm which business-critical segments they protect. Once accountable owners are identified, a remediation plan can be developed based on the assessed risk and exposure.

  • Network infrastructure teams should own remediation.
  • Verify router deployment and internet exposure.
  • Plan updates during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TOTOLINK T6 router?

The TOTOLINK T6 is a network device used primarily as a home or small office router. It manages data traffic between local devices—like computers, phones, and smart home appliances—and the internet. It provides core connectivity services, including network administration tools to restrict device access via MAC filtering, which identifies and allows or blocks specific hardware on the network.

What does CVE-2026-51715 mean by incorrect access control?

This vulnerability is classified as Improper Access Control (CWE-284). In plain terms, it means the router's software fails to verify who is making a request before performing a sensitive task. Specifically, the management function responsible for deleting MAC filter rules does not check if the user is authorized to perform that action, allowing anyone to delete these security rules without a password.

How is this vulnerability triggered?

An attacker triggers this flaw by sending a specifically formatted POST request to the router's web-based management interface. Because the system lacks proper authentication checks, it executes the command immediately upon receiving the request. Simply browsing the web or using the network does not trigger this; the attacker must specifically target the administrative path designated for managing filter rules.

Why should I care about this router vulnerability?

According to Halo Surface Signal, this vulnerability is highly relevant because the TOTOLINK T6 is designed to be internet-facing. As a gateway between the internet and your local network, its management interface is often reachable via standard web requests from outside your perimeter. If your device is accessible from the internet, an unauthenticated attacker could potentially bypass your configured security restrictions.

How do I address this security issue?

Your first step is to locate all TOTOLINK T6 routers within your environment. Once identified, determine if they are exposed directly to the internet or if they reside behind other security controls. Assess their role in protecting sensitive network segments, and coordinate with the team responsible for infrastructure maintenance to plan for updates or configuration changes during your next available maintenance window.

References