CVE-2026-51627
moderateUnauthenticated Config Disclosure in TOTOLINK T6 Router (getIptvCfg)
CVE-2026-51627 is an improper access control flaw (CWE-284) in the getIptvCfg function of the cstecgi.cgi web management interface on TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. An unauthenticated remote attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and the device returns its IPTV and IGMP configuration without requiring any credentials. The impact is limited to information disclosure (CVSS 3.1 confidentiality-only, scored 7.5 high), with no integrity or availability effects, but the leaked settings can help attackers map or further target the network. Any TOTOLINK T6 deployment on the named firmware that exposes its web management interface, particularly on the WAN side, is affected. As of now there is no public proof-of-concept, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only about a 0.4% chance of exploitation within 30 days, so no exploitation is known.
What to do: Inventory your environment for TOTOLINK T6 routers and check the firmware version; if it is 4.1.5cu.748_B20211015 (or you cannot confirm), check TOTOLINK's website for a fixed firmware release and upgrade when one becomes available, since no fixed version is specified in the available data. Until then, restrict the router's management interface to the LAN side (or management VPN) and block or firewall inbound access to the web interface on the WAN, which prevents unauthenticated remote exploitation. Monitor vendor advisories and threat feeds for updated affected-version ranges or confirmation of active exploitation.
| TOTOLINK T6 router (web management interface, getIptvCfg function in /cgi-bin/cstecgi.cgi) | 4.1.5cu.748_B20211015 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IPTV and IGMP configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.