CVE-2026-51626
moderateUnauthenticated WPS config and PIN disclosure in TOTOLINK T6 router
CVE-2026-51626 is an improper access control flaw (CWE-284) in the getWiFiWpsCfg handler of the TOTOLINK T6 web management API, which fails to require authentication for WPS configuration queries. An attacker triggers it by sending a crafted, unauthenticated POST request to /cgi-bin/cstecgi.cgi on the device's management interface. The response leaks the WPS configuration, including the current WPS PIN, potentially allowing a nearby attacker to join the protected wireless network or tamper with WPS settings. Affected are TOTOLINK T6 devices running firmware 4.1.5cu.748_B20211015; only this version is documented, though other builds may also be affected. There is no public proof-of-concept, no known in-the-wild exploitation, and the flaw is not in CISA KEV, with EPSS estimating only about a 0.4% probability of exploitation in the next 30 days.
What to do: TOTOLINK T6 owners should check their firmware version and install the latest firmware from TOTOLINK when a fixed release is published (no fixed version is specified in the available data). Until patched, avoid exposing the device's management web interface to untrusted networks or the WAN, and disable WPS or rotate the WPS PIN, since the flaw reveals it. Monitor for unauthenticated POST requests to /cgi-bin/cstecgi.cgi on the device.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (the only version documented; other firmware builds may also be affected) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS configuration, including the current PIN, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.