Description
Incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to open a wireless pairing window via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
Published: 2026-08-31
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi, which opens a wireless pairing window. Opening this window allows an attacker to begin a WPS session, potentially adding a malicious device or gaining early network access before authentication. This increases the risk of unauthorized network connectivity and could serve as a foothold for further attacks.

Affected Systems

The flaw affects TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. No other vendors or products are currently listed as vulnerable. If additional firmware versions are discovered, they may also be susceptible.

Risk and Exploitability

No CVSS score or EPSS value is publicly available, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the exploit requires only a crafted HTTP request, an attacker with access to the router’s management interface—either on the local network or over an exposed Internet interface—could activate the pairing window. The absence of a patch or workaround means the risk is moderate to high for exposed devices, while internal users may still be impacted if WPS is enabled.

Generated by OpenCVE AI on August 31, 2026 at 17:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable Wi‑Fi Protected Setup (WPS) on the device.
  • Upgrade the router to the latest firmware released by TOTOLINK that addresses the access‑control flaw.
  • Restrict administrative access to the router’s web interface by applying firewall rules that block external or public network traffic.

Generated by OpenCVE AI on August 31, 2026 at 17:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Open Wi‑Fi Pairing Window via Incorrect Access Control in TOTOLINK T6
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Mon, 31 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to open a wireless pairing window via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T15:53:30.172Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51711

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T16:18:36.223

Modified: 2026-08-31T16:18:36.223

Link: CVE-2026-51711

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T17:30:03Z

Weaknesses