CVE-2026-51708
moderateUnauthenticated access-control flaw in TOTOLINK T6 allows WPS setting changes
CVE-2026-51708 is an incorrect access control flaw (CWE-284) in the setWiFiWpsCfg function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted POST request to the router's /cgi-bin/cstecgi.cgi endpoint, requiring no credentials or user interaction. A successful request lets the attacker change the router's WPS availability (enabling or disabling the WPS setup mechanism), potentially altering the wireless setup posture of the device; the flaw carries a critical CVSS 3.1 score of 9.8, though the described functional impact is limited to WPS configuration. Any TOTOLINK T6 unit running the named firmware build is affected, particularly units whose web management interface is reachable from untrusted networks. No public proof-of-concept, KEV listing, or confirmed exploitation is known, and EPSS puts 30-day exploitation probability at just 0.4%.
What to do: Check whether your T6 runs firmware 4.1.5cu.748_B20211015 and consult TOTOLINK's website or support for a patched firmware release, since no fixed version is named in the available data. Do not expose the router's web administration interface (cgi-bin/cstecgi.cgi) to the WAN, restrict it to trusted LAN/management access, and verify WPS settings for unexpected changes; disabling WPS entirely reduces exposure to this flaw and to WPS brute-force attacks.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (only this firmware build is named in the advisory; other builds/versions are not specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change WPS availability via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.