Description
Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter IPTV service configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized configuration modification
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the setIptvCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and bypass authentication to alter IPTV service configuration. Because the configuration can be changed without authorization, the attacker could disrupt the IPTV service, redirect streams, or potentially expose sensitive network traffic, thereby compromising confidentiality, integrity, and availability of the service. The weakness is an improper access control flaw that permits unauthorized modification of system settings.

Affected Systems

The affected product is the TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other versions or product variants are explicitly listed in the CVE data. Organizations using this specific firmware should verify whether the router is deployed and assess exposure.

Risk and Exploitability

An inherent CVSS score of 9.1 demonstrates severe potential impact, while the EPSS score of < 1% indicates a low probability of exploitation at present. The vulnerability is exploitable remotely via the web interface without authentication, making the attack vector straightforward for an adversary with network access to the device. The lack of designation in the CISA KEV catalog suggests no active exploitation is currently reported, but the unauthorized configuration capability represents a high risk to network control and can enable further attacks. The risk remains significant due to the ease of exploitation and the potential impact on service availability. The likely attack vector is an unauthenticated POST to the router's web interface.

Generated by OpenCVE AI on September 2, 2026 at 05:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router to a firmware revision that removes the vulnerability (check TOTOLINK official firmware releases).
  • Restrict or block access to the /cgi-bin/cstecgi.cgi endpoint with firewall rules or disable the remote management feature that exposes it.
  • Enforce authentication for all configuration changes by configuring the router to require admin credentials on the web interface or enable HTTP authentication.

Generated by OpenCVE AI on September 2, 2026 at 05:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access Control in TOTOLINK T6 IPTV Configuration

Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access Control in TOTOLINK T6 IPTV Configuration
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter IPTV service configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T14:12:53.189Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51697

cve-icon Vulnrichment

Updated: 2026-09-01T14:12:48.798Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T15:17:21.483

Modified: 2026-09-01T15:17:16.410

Link: CVE-2026-51697

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T05:45:04Z

Weaknesses