Junglewise Threat Intelligence

CVE-2026-51627: TOTOLINK T6 missing authentication in getIptvCfg function

CVE-2026-51627 · Severity: high · CVSS 7.5 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a networking device that manages IPTV and IGMP network settings. An unauthenticated attacker can remotely retrieve sensitive IPTV and IGMP configuration information by sending a specially crafted request, potentially exposing network topology and multimedia streaming setup details.

Technical details

The getIptvCfg function in the cstecgi.cgi component of TOTOLINK T6 firmware lacks proper authentication checks. An attacker can send an unauthenticated POST request to /cgi-bin/cstecgi.cgi to invoke this function and retrieve IPTV and IGMP configuration data. This is an access control vulnerability affecting firmware version 4.1.5cu.748_B20211015 and potentially other versions. The vulnerability requires only network reachability to the device and no user interaction. No patch information is currently known.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References