ZeroHour

CVE-2026-51626

moderate

Unauthenticated WPS config and PIN disclosure in TOTOLINK T6 router

CVSS 3.1
9.1 critical
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51626 is an improper access control flaw (CWE-284) in the getWiFiWpsCfg handler of the TOTOLINK T6 web management API, which fails to require authentication for WPS configuration queries. An attacker triggers it by sending a crafted, unauthenticated POST request to /cgi-bin/cstecgi.cgi on the device's management interface. The response leaks the WPS configuration, including the current WPS PIN, potentially allowing a nearby attacker to join the protected wireless network or tamper with WPS settings. Affected are TOTOLINK T6 devices running firmware 4.1.5cu.748_B20211015; only this version is documented, though other builds may also be affected. There is no public proof-of-concept, no known in-the-wild exploitation, and the flaw is not in CISA KEV, with EPSS estimating only about a 0.4% probability of exploitation in the next 30 days.

What to do: TOTOLINK T6 owners should check their firmware version and install the latest firmware from TOTOLINK when a fixed release is published (no fixed version is specified in the available data). Until patched, avoid exposing the device's management web interface to untrusted networks or the WAN, and disable WPS or rotate the WPS PIN, since the flaw reveals it. Monitor for unauthenticated POST requests to /cgi-bin/cstecgi.cgi on the device.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (the only version documented; other firmware builds may also be affected)
Estimated exposure
moderate≈ thousands of internet-exposed units (order-of-magnitude estimate; TOTOLINK devices appear in public internet scans in the tens of thousands) — Internet-wide scans have shown TOTOLINK devices numbering in the tens of thousands exposing their web API, and the cstecgi.cgi endpoint is reachable wherever management is exposed, but no published install-base or exposure figures exist…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS configuration, including the current PIN, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.