Impact
The vulnerability lies in improper access control within the getGenerateWiFiWpsPin function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and cause the device to generate and expose a new WPS PIN. This allows the attacker to authenticate to the wireless network without proper authorization, effectively bypassing network access controls. The flaw results in a loss of confidentiality for network traffic and opens the possibility for further lateral movement. The weakness is characterized by CWE‑284: Improper Access Control.
Affected Systems
Manufacturers: TOTOLINK. Product: T6 4.1.5cu.748_B20211015. The specific firmware release is cited; no other affected versions are documented, so users should verify whether they are running this exact build. Devices running different firmware may be unaffected, but absence of vendor information means unknown scope.
Risk and Exploitability
The exploit is driven by network access to the device’s CGI interface; the attacker need only send a HTTP/HTTPS POST request to the specified endpoint. Authentication is not required, making the attack trivial, especially if the administrative interface is exposed to the public or a local network. No EPSS score is provided and the vulnerability is not in the CISA KEV list, so while exploitation is likely where access is possible, the likelihood of large‑scale incidents is not quantified. The CVSS score is not defined in the input; nevertheless, the described impact combined with the lack of authentication indicates a high potential risk.
OpenCVE Enrichment