Executive brief
TOTOLINK T6 routers contain an authentication bypass vulnerability in the wireless pairing setup function. An unauthenticated attacker on the network can send a crafted request to enable WPS (Wi-Fi Protected Setup) pairing without requiring router credentials, potentially allowing unauthorized devices to connect to the network and intercept traffic.
Technical details
The vulnerability is an incorrect access control issue in the setWiFiWpsStart function exposed via the /cgi-bin/cstecgi.cgi endpoint. The function fails to validate authentication credentials before processing POST requests to enable WPS pairing. An attacker with network access can send a specially crafted POST request to activate the WPS window without authentication, bypassing intended security controls. This allows unauthorized network access and potential man-in-the-middle attacks. The issue affects TOTOLINK T6 firmware version 4.1.5cu.748_B20211015.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-08-31: disclosed