Impact
The getWiFiWpsCfg function in TOTOLINK T6 firmware contains improper access control that permits unauthenticated attackers to retrieve the device’s WPS configuration, including the current PIN, through a crafted HTTP POST request. This flaw exposes sensitive network credentials, enabling an attacker to join the local network or launch further attacks on connected devices. The vulnerability is classified as a confidentiality breach caused by failure to enforce proper authorization checks during configuration retrieval.
Affected Systems
The vulnerability affects the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. No information about whether later firmware revisions contain the issue is available, and earlier firmware versions or other product lines may or may not be impacted.
Risk and Exploitability
The exploit requires network access to the router’s administrative interface and does not require authentication. While no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, the severity of exposing the WPS PIN suggests a high impact. Attackers can use the exposed credentials to connect to the local network, inject malicious traffic, or compromise other devices. The lack of an authentication requirement means the attack can be performed by anyone who can reach the router from the same network or via a remotely exposed management port. The vulnerability was discovered through analysis of the getWiFiWpsCfg function’s access checks.
OpenCVE Enrichment