Impact
The vulnerability stems from incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi, which opens a wireless pairing window. Opening this window allows an attacker to begin a WPS session, potentially adding a malicious device or gaining early network access before authentication. This increases the risk of unauthorized network connectivity and could serve as a foothold for further attacks.
Affected Systems
The flaw affects TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. No other vendors or products are currently listed as vulnerable. If additional firmware versions are discovered, they may also be susceptible.
Risk and Exploitability
No CVSS score or EPSS value is publicly available, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the exploit requires only a crafted HTTP request, an attacker with access to the router’s management interface—either on the local network or over an exposed Internet interface—could activate the pairing window. The absence of a patch or workaround means the risk is moderate to high for exposed devices, while internal users may still be impacted if WPS is enabled.
OpenCVE Enrichment