External risk intelligence

TOTOLINK T6 Incorrect Access Control in setWiFiWpsStart

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-51711

The vulnerability exists in a home/small office wireless router, which is typically deployed as an internet-facing gateway or network edge device. The WPS function is a standard feature of such consumer networking equipment, making the interface commonly accessible to the network environment where the device is deployed.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability impacts a common home and small office networking device, allowing unauthenticated attackers to initiate wireless pairing. The issue lies in the device's Wi-Fi Protected Setup (WPS) function, which is accessible over the network and could potentially be exploited to gain unauthorized access. The main concern is confirming relevance and exposure within our managed environment.

  • Unauthenticated access to Wi-Fi setup.
  • Exploitable on network-facing devices.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a specially crafted request to the device over the network. This request targets the WPS pairing function, which lacks proper authorization checks. If successful, the attacker can initiate a wireless pairing process, potentially gaining unauthorized access or control.

  • Unauthenticated network access required.
  • Triggered by a POST request to `/cgi-bin/cstecgi.cgi`.
  • Risk of unauthorized access and control.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker could trigger a wireless pairing window by sending a specially crafted POST request to the router. This could potentially allow an attacker to initiate a Wi-Fi Protected Setup (WPS) session without proper authorization when supported by the advisory.

  • Router configuration and network access.
  • Sending a crafted POST request.
  • Unauthorized initiation of WPS pairing.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in TOTOLINK routers impacts network infrastructure. Responsibility likely falls to network or infrastructure teams, with potential vendor coordination for a fix. The first step is to identify affected devices, confirm their exposure and criticality, and then plan remediation based on that risk assessment.

  • Own by infrastructure or network teams.
  • Verify device reachability and business impact.
  • Plan remediation or vendor engagement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TOTOLINK T6?

The TOTOLINK T6 is a wireless router designed for home and small office environments. It serves as a central network gateway, managing internet connectivity and wireless access for connected devices. Like many routers, it includes convenience features such as Wi-Fi Protected Setup (WPS) to simplify the process of adding new devices to the network.

What does CVE-2026-51711 mean?

This CVE identifies an improper access control vulnerability (CWE-284). In simple terms, the router's software fails to verify if a user is authorized before performing a specific action. Because this check is missing, the device allows an unauthenticated person to trigger the Wi-Fi pairing process, which is intended to be protected.

How is the WPS function triggered?

An attacker triggers this bug by sending a specially crafted POST request to the router's CGI interface. It is important to note that the vulnerability is specific to this programmatic request; normal interactions with the device's web interface or hardware buttons for legitimate WPS activation are distinct from this unauthorized command path.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal indicates that because the TOTOLINK T6 is typically deployed as an internet-facing gateway, it is often exposed to the network environment. If your device is configured to allow network access to its management interface, it is more likely to be reachable by an attacker, making this a relevant concern for your perimeter security.

What should I do if I use this router?

First, verify if your network infrastructure utilizes the affected TOTOLINK T6 model. Once identified, assess whether the management interface is accessible from outside your immediate control. Since this is a critical access control issue, prioritize identifying these assets and contact the manufacturer or check their support portal for available firmware updates.

References