CVE-2026-51626
TOTOLINK · T6
TOTOLINK T6 routers contain an incorrect access control flaw in the getWiFiWpsCfg function, allowing unauthenticated attackers to retrieve WPS configuration data and the PIN via crafted POST requests.
Executive summary
An unauthenticated access control vulnerability in TOTOLINK T6 routers allows remote attackers to exfiltrate sensitive Wi-Fi configuration data, including the WPS PIN, posing a critical security risk.
Vulnerability
The device suffers from an incorrect access control issue within the getWiFiWpsCfg function. Unauthenticated attackers can trigger this flaw by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to extract sensitive wireless security settings.
Business impact
The exposure of WPS configuration and PINs allows unauthorized parties to compromise the confidentiality of the wireless network. With a CVSS score of 9.1, this vulnerability is critical, as it enables attackers to bypass authentication mechanisms and potentially gain unauthorized access to the network infrastructure, leading to broader data breaches or internal network exploitation.
Remediation
Immediate Action: Review the official TOTOLINK support portal for available firmware updates addressing this vulnerability and apply them immediately to the affected hardware.
Proactive Monitoring: Monitor network traffic for anomalous POST requests directed toward the /cgi-bin/cstecgi.cgi endpoint, which may indicate attempted exploitation.
Compensating Controls: Disable the WPS feature on the router interface if it is not strictly required for business operations, as this effectively eliminates the attack vector.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the critical severity of this access control flaw, administrators must prioritize identifying all deployed TOTOLINK T6 units. In the absence of a confirmed patch, restricting network access to the management interface is a necessary security measure to prevent unauthenticated access by remote adversaries. Monitor vendor communications closely for the release of security-hardened firmware.