Description
Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-28
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in improper access control within the getGenerateWiFiWpsPin function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and cause the device to generate and expose a new WPS PIN. This allows the attacker to authenticate to the wireless network without proper authorization, effectively bypassing network access controls. The flaw results in a loss of confidentiality for network traffic and opens the possibility for further lateral movement. The weakness is characterized by CWE‑284: Improper Access Control.

Affected Systems

Manufacturers: TOTOLINK. Product: T6 4.1.5cu.748_B20211015. The specific firmware release is cited; no other affected versions are documented, so users should verify whether they are running this exact build. Devices running different firmware may be unaffected, but absence of vendor information means unknown scope.

Risk and Exploitability

The exploit is driven by network access to the device’s CGI interface; the attacker need only send a HTTP/HTTPS POST request to the specified endpoint. Authentication is not required, making the attack trivial, especially if the administrative interface is exposed to the public or a local network. No EPSS score is provided and the vulnerability is not in the CISA KEV list, so while exploitation is likely where access is possible, the likelihood of large‑scale incidents is not quantified. The CVSS score is not defined in the input; nevertheless, the described impact combined with the lack of authentication indicates a high potential risk.

Generated by OpenCVE AI on August 28, 2026 at 20:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply any official firmware update from TOTOLINK that addresses the getGenerateWiFiWpsPin access control flaw.
  • If no update is available, block external access to the /cgi-bin/cstecgi.cgi endpoint or the entire administrative interface via firewall or network segmentation.
  • Disable the WPS feature on the device if it is not required; this removes the attack surface that relies on WPS PIN generation.

Generated by OpenCVE AI on August 28, 2026 at 20:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated POST Generates WPS PIN on TOTOLINK T6
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-28T16:05:14.269Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51628

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-28T20:18:06.040

Modified: 2026-08-28T21:25:22.770

Link: CVE-2026-51628

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:45:04Z

Weaknesses