Description
Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change WPS availability via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi and change the Wi‑Fi Protected Setup (WPS) availability setting. The attacker can enable or disable WPS without authentication, potentially exposing the network to brute‑force attacks or disrupting legitimate WPS usage. This results in unauthorized configuration modification, affecting the confidentiality of network connectivity and the availability of configuration services.

Affected Systems

Affected device: TOTOLINK T6 router running firmware version 4.1.5cu.748_B20211015. No other product versions are mentioned and no other vendors are affected.

Risk and Exploitability

The vulnerability is local to the device’s management interface and can be triggered without authentication; the attack vector is network based. An attacker who can reach the device can modify WPS settings by sending a POST request to a known CGI endpoint. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, so the exact likelihood of exploitation is uncertain. Nonetheless, any unauthenticated attacker with network access can disrupt or enable WPS, leading to denial of service or unauthorized access if the router is misconfigured.

Generated by OpenCVE AI on August 31, 2026 at 16:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to the latest vendor release once it becomes available.
  • If a firmware update is not yet available, disable the WPS feature through the router’s web interface to prevent unauthorized toggling.
  • Restrict access to the router’s management interface by firewall rules or VLAN segmentation so that only trusted devices can reach the CGI endpoint.
  • Verify that all administrative changes are protected by strong authentication and that proper access control checks are enforced on configuration endpoints.

Generated by OpenCVE AI on August 31, 2026 at 16:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Toggle WPS on TOTOLINK T6
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change WPS availability via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T15:25:26.424Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51708

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T16:18:35.897

Modified: 2026-08-31T16:18:35.897

Link: CVE-2026-51708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T16:30:05Z

Weaknesses