ZeroHour

CVE-2026-51711

large

Unauthenticated access-control flaw in TOTOLINK T6 router allows WPS pairing abuse

CVSS 3.1
9.1 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-51711 is an improper access-control flaw (CWE-284) in the setWiFiWpsStart function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. A remote, unauthenticated attacker can trigger it by sending a crafted POST request to the router's management endpoint /cgi-bin/cstecgi.cgi. Successful exploitation opens the wireless (WPS) pairing window without authentication, allowing the attacker to initiate a WPS pairing session, which the CVSS scoring reflects as high impact on confidentiality and integrity (e.g., enabling unauthorized devices to associate or WPS PIN-based attacks) with no availability impact. Owners of TOTOLINK T6 routers are affected; the data confirms only firmware 4.1.5cu.748_B20211015, and the status of other versions is not stated. Exploitation has not been reported: there is no known public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS estimates only a ~0.3% chance of exploitation in the next 30 days.

What to do: Check the firmware version in the router's admin interface and, when TOTOLINK publishes a fix, update to a release newer than 4.1.5cu.748_B20211015 (no fixed version is given in the available data). Until patched, restrict exposure of the web management interface (disable WAN-side/remote management) and consider disabling WPS, since the flaw lets unauthenticated users open the WPS pairing window.

Affected
TOTOLINK T6 router4.1.5cu.748_B20211015 (firmware cited in the advisory; other version ranges not confirmed in available data)
Estimated exposure
large≈10,000–100,000 deployed devices, with only a subset likely internet-exposed — TOTOLINK's budget consumer routers routinely appear in public internet scans in the tens of thousands across the product line, but no per-model install count is published for the T6, so this is an order-of-magnitude estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to open a wireless pairing window via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.