CVE-2026-51731 is an improper access control vulnerability (CWE-284) in the delVlanCfg function of the TOTOLINK T6 router's web management CGI interface, running firmware version 4.1.5cu.748_B20211015. The flaw allows an unauthenticated, remote attacker to delete VLAN configuration entries by sending a crafted POST request to /cgi-bin/cstecgi.cgi. The vulnerability carries a CRITICAL CVSS v3.1 base score of 9.1.
