Junglewise Threat Intelligence

CVE-2026-51711: TOTOLINK T6 authentication bypass in setWiFiWpsStart

CVE-2026-51711 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

TOTOLINK T6 routers contain an authentication bypass vulnerability in the wireless pairing setup function. An unauthenticated attacker on the network can send a crafted request to enable WPS (Wi-Fi Protected Setup) pairing without requiring router credentials, potentially allowing unauthorized devices to connect to the network and intercept traffic.

Technical details

The vulnerability is an incorrect access control issue in the setWiFiWpsStart function exposed via the /cgi-bin/cstecgi.cgi endpoint. The function fails to validate authentication credentials before processing POST requests to enable WPS pairing. An attacker with network access can send a specially crafted POST request to activate the WPS window without authentication, bypassing intended security controls. This allows unauthorized network access and potential man-in-the-middle attacks. The issue affects TOTOLINK T6 firmware version 4.1.5cu.748_B20211015.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-31: disclosed

References