CRITICAL 9.1 CVE-2026-51726 Published 31 Aug 2026

TOTOLINK T6 Parental Control Bypass

Worried this affects one of your servers?

A vulnerability in TOTOLINK T6 firmware allows unauthenticated attackers to remove parental-control rules.

An incorrect access control issue in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 enables attackers to send a crafted POST request to /cgi-bin/cstecgi.cgi and remove parental-control rules without authentication.

Reference: CVE-2026-51726 on NVD

← Back to Security News