CVE-2026-51744
nicheUnauthenticated access-control flaw in TOTOLINK T6 mesh sync via MQTT
CVE-2026-51744 is an incorrect access control flaw (CWE-284) in the recv_mesh_info_sync function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted MQTT message to the device's cs_broker component, which forces the router to synchronize its mesh configuration from a host the attacker controls. A successful attack lets the attacker push or alter mesh configuration data on the device without credentials; the 9.8 CVSS score indicates high potential impact across confidentiality, integrity, and availability, though no public proof-of-concept demonstrates deeper compromise. Only the TOTOLINK T6 with the documented firmware version is confirmed affected, and the vendor's full affected or fixed version scope is not stated in the available data. No exploitation has been reported: the flaw is not in CISA's KEV catalog, no public PoC is known, and EPSS assigns roughly a 0.4% probability of exploitation within 30 days.
What to do: TOTOLINK T6 owners should check their current firmware version and update to the latest release published by TOTOLINK (no fixed version is identified in the available data), and monitor vendor advisories for scope updates. To limit remote triggering, avoid exposing the router's management and MQTT interfaces to the internet and restrict cs_broker reachability to trusted LAN hosts.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronization from an attacker-controlled host via sending a crafted MQTT message to the cs_broker component.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.