CVE-2026-51697
TOTOLINK · T6
TOTOLINK T6 routers contain an incorrect access control vulnerability in the setIptvCfg function, allowing unauthenticated attackers to modify IPTV configurations via crafted POST requests.
Executive summary
An unauthenticated access control vulnerability in TOTOLINK T6 routers poses a critical risk of unauthorized configuration manipulation and potential service disruption.
Vulnerability
The vulnerability exists in the setIptvCfg function of the device firmware. It allows an unauthenticated attacker to send a malicious POST request to the /cgi-bin/cstecgi.cgi endpoint, bypassing security controls to alter sensitive IPTV service settings.
Business impact
The exploitation of this flaw can lead to unauthorized modification of network configurations, potentially resulting in service outages or the redirection of traffic. With a CVSS score of 9.1, this vulnerability is classified as critical due to the lack of authentication required for exploitation, which significantly lowers the barrier for attackers to gain control over device functionality.
Remediation
Immediate Action: Consult the official TOTOLINK support portal to determine if a firmware update addressing this specific configuration bypass is available for your hardware revision.
Proactive Monitoring: Monitor network traffic for anomalous POST requests directed toward the /cgi-bin/cstecgi.cgi endpoint, which may indicate attempted exploitation.
Compensating Controls: Restrict administrative access to the router interface to trusted internal IP addresses only, and ensure the device is not exposed directly to the public internet.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical CVSS severity and the ease of access for unauthenticated attackers, administrators should prioritize securing the management interface of affected TOTOLINK T6 devices. If no vendor patch is currently available, isolating the management interface from external networks is the most effective method to mitigate the risk of unauthorized configuration changes.