CVE-2026-51711

TOTOLINK · T6

An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to trigger a wireless pairing window via a crafted POST request.

Executive summary

A critical access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to remotely initiate wireless pairing, potentially facilitating unauthorized network access.

Vulnerability

This vulnerability resides in the setWiFiWpsStart function of the device firmware. It allows an unauthenticated attacker to send a specially crafted POST request to the /cgi-bin/cstecgi.cgi endpoint to activate the Wi-Fi Protected Setup (WPS) pairing process.

Business impact

The ability for an unauthenticated remote attacker to force a wireless pairing state poses a significant risk to network security. By manipulating the WPS function, an attacker could potentially bypass authentication mechanisms to gain unauthorized access to the local wireless network. With a CVSS score of 9.1, this vulnerability is classified as critical, as it provides a low-complexity vector for compromising the confidentiality and integrity of network communications.

Remediation

Immediate Action: Consult the official TOTOLINK support portal for firmware updates or security patches for the T6 model. If no patch is available, disable the WPS functionality within the router settings to prevent exploitation.

Proactive Monitoring: Review device access logs for suspicious POST requests targeting the /cgi-bin/cstecgi.cgi endpoint. Monitor for unexpected activation of the WPS pairing status on the device.

Compensating Controls: Restrict access to the router management interface to trusted internal IP addresses only. Implement network segmentation to ensure that unauthorized wireless associations do not grant immediate access to sensitive internal resources.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical severity of this vulnerability, administrators should prioritize securing affected TOTOLINK T6 devices immediately. If a vendor-provided firmware update is not currently available, disabling the WPS feature is the most effective method to neutralize this attack vector. Continuous monitoring of network traffic for unauthorized pairing attempts is recommended until a permanent patch can be applied.

More TOTOLINK CVEs

Sources