ZeroHour

CVE-2026-51708

moderate

Unauthenticated access-control flaw in TOTOLINK T6 allows WPS setting changes

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51708 is an incorrect access control flaw (CWE-284) in the setWiFiWpsCfg function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, requiring no credentials or user interaction. A successful request lets the attacker change the router's WPS availability (enabling or disabling the WPS setup mechanism), potentially altering the wireless setup posture of the device; the flaw carries a critical CVSS 3.1 score of 9.8, though the described functional impact is limited to WPS configuration. Any TOTOLINK T6 unit running the named firmware build is affected, particularly units whose web management interface is reachable from untrusted networks. No public proof-of-concept, KEV listing, or confirmed exploitation is known, and EPSS puts 30-day exploitation probability at just 0.4%.

What to do: Check whether your T6 runs firmware 4.1.5cu.748_B20211015 and consult TOTOLINK's website or support for a patched firmware release, since no fixed version is named in the available data. Do not expose the router's web administration interface (cgi-bin/cstecgi.cgi) to the WAN, restrict it to trusted LAN/management access, and verify WPS settings for unexpected changes; disabling WPS entirely reduces exposure to this flaw and to WPS brute-force attacks.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (only this firmware build is named in the advisory; other builds/versions are not specified)
Estimated exposure
moderatelikely on the order of tens of thousands of units deployed (budget-tier consumer router; TOTOLINK devices commonly appear in the tens of thousands in public… — No vendor install figures are available, so the estimate is based on TOTOLINK's positioning as a low-cost consumer router brand with broad distribution and on typical counts of internet-exposed TOTOLINK devices observed in public scans, of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change WPS availability via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.