Sceawere

Vulnerability Detail

CVE-2026-51708UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TOTOLINK T6 WPS Access Control

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
1d ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change WPS availability via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-31T16:18:35.897Z",
  "pubdate": "2026-08-31T16:18:35.897Z",
  "executiveSummary": "This vulnerability involves an improper access control flaw within the TOTOLINK T6 firmware version 4.1.5cu.748_B20211015, specifically residing in the setWiFiWpsCfg function.\nThe vulnerability allows unauthenticated remote attackers to modify the WPS (Wi-Fi Protected Setup) availability state by submitting a maliciously crafted POST request to the cgi-bin/cstecgi.cgi endpoint.\nThe primary risk stems from the lack of authentication mechanisms protecting critical device configuration interfaces. By manipulating the WPS configuration, an attacker can bypass standard security controls or enable features that may facilitate further network penetration.\nThe exploit does not require prior knowledge of device credentials, allowing unauthorized external actors to modify router settings directly. This lack of authentication presents a significant security risk for the integrity and confidentiality of the affected device and its associated network.",
  "technicalDetails": "The vulnerability originates from a failure to enforce authorization checks within the setWiFiWpsCfg function, which is responsible for processing WPS configuration parameters on the TOTOLINK T6 device.\nThe web interface handles administrative tasks via the /cgi-bin/cstecgi.cgi endpoint. Analysis of the backend code reveals that the function responsible for processing POST requests does not validate the session state or verify the identity of the requester before applying configuration changes.\nThe attack flow begins when an attacker sends an unauthenticated HTTP POST request to the /cgi-bin/cstecgi.cgi URI. The request body contains parameters designed to interact with the setWiFiWpsCfg function. Because the function lacks the necessary access control logic (specifically a middleware or handler check for valid session tokens or authentication cookies), the underlying system executes the requested configuration change.\nThe vulnerable component is the cgi-bin handler, which improperly delegates the WPS configuration state change to a function that assumes it is already operating within a secure, authenticated context. By crafting a POST payload that targets specific WPS variables, an attacker can forcibly enable or disable WPS functionality remotely.\nSuccessful exploitation results in the unauthorized modification of device firmware settings. Although this specific vulnerability allows for the toggle of WPS, it highlights a broader architectural weakness regarding the exposure of administrative functions via cgi-bin endpoints without enforced authentication. This could serve as a precursor to more complex attacks, such as exploiting WPS-based security weaknesses to gain further unauthorized access to the network or perform secondary device compromises.\nThe exposure is network-based; any attacker with connectivity to the administrative interface of the router can trigger this functionality. There are no privilege requirements, as the vulnerability resides at the gateway of the request processing logic, effectively bypassing the intended security architecture."
}
CVE-2026-51708: TOTOLINK T6 WPS Access Control (CRITICAL Severity, CVSS: 9.8) - Sceawere