CVE-2026-51626

TOTOLINK · T6

TOTOLINK T6 routers contain an incorrect access control flaw in the getWiFiWpsCfg function, allowing unauthenticated attackers to retrieve WPS configuration data and the PIN via crafted POST requests.

Executive summary

An unauthenticated access control vulnerability in TOTOLINK T6 routers allows remote attackers to exfiltrate sensitive Wi-Fi configuration data, including the WPS PIN, posing a critical security risk.

Vulnerability

The device suffers from an incorrect access control issue within the getWiFiWpsCfg function. Unauthenticated attackers can trigger this flaw by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to extract sensitive wireless security settings.

Business impact

The exposure of WPS configuration and PINs allows unauthorized parties to compromise the confidentiality of the wireless network. With a CVSS score of 9.1, this vulnerability is critical, as it enables attackers to bypass authentication mechanisms and potentially gain unauthorized access to the network infrastructure, leading to broader data breaches or internal network exploitation.

Remediation

Immediate Action: Review the official TOTOLINK support portal for available firmware updates addressing this vulnerability and apply them immediately to the affected hardware.

Proactive Monitoring: Monitor network traffic for anomalous POST requests directed toward the /cgi-bin/cstecgi.cgi endpoint, which may indicate attempted exploitation.

Compensating Controls: Disable the WPS feature on the router interface if it is not strictly required for business operations, as this effectively eliminates the attack vector.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical severity of this access control flaw, administrators must prioritize identifying all deployed TOTOLINK T6 units. In the absence of a confirmed patch, restricting network access to the management interface is a necessary security measure to prevent unauthenticated access by remote adversaries. Monitor vendor communications closely for the release of security-hardened firmware.

More TOTOLINK CVEs

Sources