Executive brief
TOTOLINK T6 is a wireless router used in homes and small businesses to provide internet connectivity. An unauthenticated attacker on the local network can retrieve sensitive WiFi Protected Setup (WPS) configuration data, including the current PIN, which can be used to compromise the wireless network and gain unauthorized access.
Technical details
This vulnerability is an authentication bypass in the getWiFiWpsCfg CGI function of cstecgi.cgi. An attacker can send an unauthenticated POST request to /cgi-bin/cstecgi.cgi to retrieve WPS configuration data without providing valid credentials. The attack requires network-level access to the router (adjacent attack vector) but no authentication. By obtaining the WPS PIN, an attacker can perform WPS-based WiFi attacks or trigger PIN-brute-force attempts to join the network. This affects TOTOLINK T6 version 4.1.5cu.748_B20211015 and likely other versions. Patch availability status is unknown.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-28: disclosed