CRITICAL
9.1 CVE-2026-51726 Published 31 Aug 2026
TOTOLINK T6 Parental Control Bypass
Worried this affects one of your servers?
A vulnerability in TOTOLINK T6 firmware allows unauthenticated attackers to remove parental-control rules.
An incorrect access control issue in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 enables attackers to send a crafted POST request to /cgi-bin/cstecgi.cgi and remove parental-control rules without authentication.
Reference: CVE-2026-51726 on NVD
← Back to Security News