CVE-2026-51711
largeUnauthenticated access-control flaw in TOTOLINK T6 router allows WPS pairing abuse
CVE-2026-51711 is an improper access-control flaw (CWE-284) in the setWiFiWpsStart function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. A remote, unauthenticated attacker can trigger it by sending a crafted POST request to the router's management endpoint /cgi-bin/cstecgi.cgi. Successful exploitation opens the wireless (WPS) pairing window without authentication, allowing the attacker to initiate a WPS pairing session, which the CVSS scoring reflects as high impact on confidentiality and integrity (e.g., enabling unauthorized devices to associate or WPS PIN-based attacks) with no availability impact. Owners of TOTOLINK T6 routers are affected; the data confirms only firmware 4.1.5cu.748_B20211015, and the status of other versions is not stated. Exploitation has not been reported: there is no known public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS estimates only a ~0.3% chance of exploitation in the next 30 days.
What to do: Check the firmware version in the router's admin interface and, when TOTOLINK publishes a fix, update to a release newer than 4.1.5cu.748_B20211015 (no fixed version is given in the available data). Until patched, restrict exposure of the web management interface (disable WAN-side/remote management) and consider disabling WPS, since the flaw lets unauthenticated users open the WPS pairing window.
| TOTOLINK T6 router | 4.1.5cu.748_B20211015 (firmware cited in the advisory; other version ranges not confirmed in available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to open a wireless pairing window via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.