Impact
The vulnerability stems from incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to /cgi-bin/cstecgi.cgi, which opens a wireless pairing window. Opening this window allows an attacker to begin a WPS session, potentially adding a malicious device or gaining early network access before authentication. This increases the risk of unauthorized network connectivity and could serve as a foothold for further attacks.
Affected Systems
The flaw affects TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. No other vendors or products are currently listed as vulnerable. If additional firmware versions are discovered, they may also be susceptible.
Risk and Exploitability
The CVSS score is 9.1, indicating a critical severity. The EPSS score is <1%, suggesting a low probability that the vulnerability is actively exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the exploit requires only a crafted HTTP request, an attacker with access to the router’s management interface—either on the local network or over an exposed Internet interface—could activate the pairing window. The absence of a patch or workaround means the risk is moderate to high for exposed devices, while internal users may still be impacted if WPS is enabled.
OpenCVE Enrichment