CVE-2026-51697
largeUnauthenticated access-control flaw in TOTOLINK T6 IPTV configuration
TOTOLINK T6 router firmware 4.1.5cu.748_B20211015 contains an improper access control flaw (CWE-284) in the setIptvCfg function of its web management interface. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and modify the device's IPTV service configuration without any credentials or user interaction. Successful exploitation lets the attacker alter IPTV-related settings on the router; the CVSS 3.1 score of 9.1 (critical) with network vector and no privileges required rates confidentiality and integrity impacts as high, though the disclosed impact is configuration tampering. Affected users are homes or deployments running TOTOLINK T6 routers with this firmware, particularly where the management interface is reachable from the internet or untrusted LAN clients. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS places 30-day exploitation probability at roughly 0.3%, so no exploitation is known.
What to do: Check TOTOLINK T6 units for firmware 4.1.5cu.748_B20211015 and apply the vendor's next fixed firmware release when TOTOLINK publishes one (no fixed version is available in the current data). Until patched, do not expose the router's management interface or /cgi-bin/cstecgi.cgi to the WAN, restrict access with firewall/ACL rules, and review current IPTV configuration for unexpected changes that could indicate tampering.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 (other firmware versions may be affected but are not confirmed in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter IPTV service configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.