ZeroHour

CVE-2026-51628

moderate

Unauthenticated WPS PIN generation flaw in TOTOLINK T6 router

CVSS 3.1
9.1 critical
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51628 is an incorrect access control flaw (CWE-284) in the getGenerateWiFiWpsPin function of TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted POST request to the device's /cgi-bin/cstecgi.cgi endpoint, causing the router to generate and return a new WPS PIN without any credentials. That PIN could potentially be used with WPS to join the otherwise protected wireless network, and the critical CVSS 9.1 score reflects high confidentiality and integrity impact. Any TOTOLINK T6 running the reported firmware is affected where the web management interface is reachable, for example from the LAN or from the WAN when remote management is enabled. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates only about a 0.4% probability of exploitation within 30 days.

What to do: Until TOTOLINK publishes a patched firmware, restrict access to the router's management interface: disable remote/WAN-side management and limit cstecgi.cgi access to trusted LAN hosts, and consider disabling WPS if it is not needed. Confirm whether your T6 is running firmware 4.1.5cu.748_B20211015 and monitor the vendor for an updated release addressing this access control flaw.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (the version reported affected; no other version ranges specified)
Estimated exposure
moderateplausibly 10,000-100,000 T6 units deployed worldwide, with only the smaller subset that exposes the management interface to the WAN at direct risk — This is an order-of-magnitude estimate based on deployment patterns of a single TOTOLINK consumer router model sold in price-sensitive markets; no public install-base counts or internet-exposed device scan counts for this model were…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to generate and retrieve a new WPS PIN via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.