CVE-2026-51628
moderateUnauthenticated WPS PIN generation flaw in TOTOLINK T6 router
CVE-2026-51628 is an incorrect access control flaw (CWE-284) in the getGenerateWiFiWpsPin function of TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to the device's /cgi-bin/cstecgi.cgi endpoint, causing the router to generate and return a new WPS PIN without any credentials. That PIN could potentially be used with WPS to join the otherwise protected wireless network, and the critical CVSS 9.1 score reflects high confidentiality and integrity impact. Any TOTOLINK T6 running the reported firmware is affected where the web management interface is reachable, for example from the LAN or from the WAN when remote management is enabled. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates only about a 0.4% probability of exploitation within 30 days.
What to do: Until TOTOLINK publishes a patched firmware, restrict access to the router's management interface: disable remote/WAN-side management and limit cstecgi.cgi access to trusted LAN hosts, and consider disabling WPS if it is not needed. Confirm whether your T6 is running firmware 4.1.5cu.748_B20211015 and monitor the vendor for an updated release addressing this access control flaw.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (the version reported affected; no other version ranges specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.