Junglewise Threat Intelligence

CVE-2026-51628: TOTOLINK T6 unauthenticated WPS PIN generation in getGenerateWiFiWpsPin

CVE-2026-51628 · Severity: critical · CVSS 9.1 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a consumer WiFi router used in home and small office networks. The device's web administration interface fails to authenticate requests to generate new WPS PIN codes, allowing unauthenticated attackers on the network to generate and retrieve PIN codes that can be used to connect to the WiFi network without knowing the password. This can lead to unauthorized network access and potential compromise of connected devices and data.

Technical details

The vulnerability is an authentication bypass (missing access control) in the getGenerateWiFiWpsPin function within the cstecgi.cgi CGI endpoint of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. Unauthenticated attackers can send a crafted POST request to /cgi-bin/cstecgi.cgi to invoke this function and retrieve a newly generated WPS PIN without providing any credentials. The attack requires network access to the device (adjacent/local network) but no authentication or user interaction. A successful exploit allows an attacker to retrieve valid WPS PINs that can be used to associate with the router's WiFi network, effectively bypassing WPS security controls. No official patch information is available in the advisory.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References