Junglewise Threat Intelligence

CVE-2026-51708: TOTOLINK T6 incorrect access control in setWiFiWpsCfg

CVE-2026-51708 · Severity: critical · CVSS 9.8 · Published 2026-08-31

Executive brief

TOTOLINK T6 is a consumer WiFi router that allows administrators to configure WPS (WiFi Protected Setup) security settings. An unauthenticated attacker can disable or enable WPS directly by sending a specially crafted request to the device's web interface, bypassing login requirements entirely. This gives attackers an easy foothold to conduct brute-force attacks against the WiFi network.

Technical details

The vulnerability is an authentication bypass / missing access control in the setWiFiWpsCfg function exposed via the /cgi-bin/cstecgi.cgi endpoint on TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can send a POST request to modify WPS configuration without providing any credentials. The vulnerable CGI script fails to check user authentication before processing configuration changes. An attacker with network access to the device can change WPS settings, making the WiFi network more vulnerable to unauthorized connection attempts via WPS brute-force attacks.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References