External risk intelligence

TOTOLINK T6 VLAN Removal Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-51731

The vulnerability exists in a home/small office router product and is exploitable via a web-based CGI interface. Such network devices and their management interfaces are commonly exposed to the internet or edge networks in typical deployment scenarios.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An unauthenticated access control vulnerability in a TOTOLINK product could allow unauthorized removal of network configuration entries. While the specific business impact is unconfirmed, the ability for an external attacker to alter network settings remotely warrants attention to confirm relevance and exposure.

  • Attackers can change network settings remotely.
  • This could disrupt network operations.
  • Confirm relevance and assess exposure risk.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request to the `/cgi-bin/cstecgi.cgi` endpoint. This request targets the `delVlanCfg` function, which suffers from improper access controls. Successful exploitation allows the attacker to remove VLAN entries, potentially disrupting network configurations.

  • No authentication required.
  • Send crafted POST request to CGI endpoint.
  • Unauthenticated VLAN configuration removal.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to remove VLAN entries on affected devices. This could impact network segmentation and potentially disrupt network connectivity for users.

  • Network configuration data.
  • Via crafted POST request.
  • Disrupt network segmentation.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world ownership of this vulnerability likely falls to network infrastructure or device management teams responsible for managing TOTOLINK devices. The first practical step is to identify all instances of the affected device, determine their exposure and criticality, and then confirm the accountable owner before planning remediation.

  • Network infrastructure teams own the issue.
  • Verify device exposure and business criticality.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TOTOLINK T6 router?

The TOTOLINK T6 is a networking device typically deployed in homes or small offices to manage internet connectivity. It functions as a router, handling traffic routing, network segmentation, and wireless access for connected devices.

What does CVE-2026-51731 mean?

This CVE identifies a flaw categorized as Improper Access Control (CWE-284). In plain terms, the software fails to verify who is making a request before performing a sensitive task, specifically allowing unauthorized changes to the device's configuration.

How can an attacker trigger this vulnerability?

An attacker can trigger the issue by sending a specially crafted POST request to the device's CGI management interface. The bug is limited to the 'delVlanCfg' function, meaning it specifically targets VLAN entries; requests that do not interact with this function or attempt to modify other settings do not trigger this vulnerability.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal notes that because this is a router with a web-based management interface, these devices are frequently deployed on the edge of networks. If your device is configured to be accessible from the internet rather than restricted to an internal-only management network, your risk of exposure is higher.

What steps should I take if I use this TOTOLINK device?

Start by identifying all instances of the T6 within your network environment. Evaluate whether these devices are reachable from the internet, as this impacts the immediate risk level. Locate the official vendor support pages to monitor for any available firmware updates or security guidance from TOTOLINK.

References