CVE-2026-51697

TOTOLINK · T6

TOTOLINK T6 routers contain an incorrect access control vulnerability in the setIptvCfg function, allowing unauthenticated attackers to modify IPTV configurations via crafted POST requests.

Executive summary

An unauthenticated access control vulnerability in TOTOLINK T6 routers poses a critical risk of unauthorized configuration manipulation and potential service disruption.

Vulnerability

The vulnerability exists in the setIptvCfg function of the device firmware. It allows an unauthenticated attacker to send a malicious POST request to the /cgi-bin/cstecgi.cgi endpoint, bypassing security controls to alter sensitive IPTV service settings.

Business impact

The exploitation of this flaw can lead to unauthorized modification of network configurations, potentially resulting in service outages or the redirection of traffic. With a CVSS score of 9.1, this vulnerability is classified as critical due to the lack of authentication required for exploitation, which significantly lowers the barrier for attackers to gain control over device functionality.

Remediation

Immediate Action: Consult the official TOTOLINK support portal to determine if a firmware update addressing this specific configuration bypass is available for your hardware revision.

Proactive Monitoring: Monitor network traffic for anomalous POST requests directed toward the /cgi-bin/cstecgi.cgi endpoint, which may indicate attempted exploitation.

Compensating Controls: Restrict administrative access to the router interface to trusted internal IP addresses only, and ensure the device is not exposed directly to the public internet.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical CVSS severity and the ease of access for unauthenticated attackers, administrators should prioritize securing the management interface of affected TOTOLINK T6 devices. If no vendor patch is currently available, isolating the management interface from external networks is the most effective method to mitigate the risk of unauthorized configuration changes.

More TOTOLINK CVEs all →

Sources