Executive brief
The TOTOLINK T6 router's web administration interface lacks authentication checks on a critical configuration function that manages IPTV service settings. An attacker on the network can change IPTV configuration without credentials, potentially disrupting TV service delivery, redirecting traffic to malicious servers, or denying legitimate subscribers access to their IPTV services.
Technical details
The setIptvCfg function in /cgi-bin/cstecgi.cgi fails to perform authentication checks before processing requests to modify IPTV configuration. An unauthenticated attacker can send a crafted POST request to alter these settings without providing valid login credentials. The vulnerability requires only network access to the router's web interface (typically accessible on the LAN). An attacker can modify IPTV service parameters including server URLs, credentials, or access control, leading to service manipulation or denial of service. No patch status is indicated in the available reference material.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed
- 2026-08-31: advisory