ZeroHour

CVE-2026-51627

moderate

Unauthenticated Config Disclosure in TOTOLINK T6 Router (getIptvCfg)

CVSS 3.1
7.5 high
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51627 is an improper access control flaw (CWE-284) in the getIptvCfg function of the cstecgi.cgi web management interface on TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. An unauthenticated remote attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and the device returns its IPTV and IGMP configuration without requiring any credentials. The impact is limited to information disclosure (CVSS 3.1 confidentiality-only, scored 7.5 high), with no integrity or availability effects, but the leaked settings can help attackers map or further target the network. Any TOTOLINK T6 deployment on the named firmware that exposes its web management interface, particularly on the WAN side, is affected. As of now there is no public proof-of-concept, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only about a 0.4% chance of exploitation within 30 days, so no exploitation is known.

What to do: Inventory your environment for TOTOLINK T6 routers and check the firmware version; if it is 4.1.5cu.748_B20211015 (or you cannot confirm), check TOTOLINK's website for a fixed firmware release and upgrade when one becomes available, since no fixed version is specified in the available data. Until then, restrict the router's management interface to the LAN side (or management VPN) and block or firewall inbound access to the web interface on the WAN, which prevents unauthenticated remote exploitation. Monitor vendor advisories and threat feeds for updated affected-version ranges or confirmation of active exploitation.

Affected
TOTOLINK T6 router (web management interface, getIptvCfg function in /cgi-bin/cstecgi.cgi)4.1.5cu.748_B20211015
Estimated exposure
moderatelikely on the order of thousands of internet-exposed TOTOLINK T6 devices (exact count unknown) — TOTOLINK consumer routers routinely appear in public internet-wide scans in the tens of thousands across all models, and the T6 is among the commonly seen models, so the exposed subset plausibly affected by this flaw is estimated in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IPTV and IGMP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.