CVE-2026-51751
largeUnauthenticated MQTT access-control flaw in TOTOLINK T6 mesh router
CVE-2026-51751 is an incorrect access-control flaw (CWE-284) in the delSlaveDevice function of the cs_broker component in TOTOLINK T6 mesh routers running firmware 4.1.5cu.748_B20211015, rated 9.8 Critical under CVSS 3.1. An unauthenticated attacker who can reach the device's MQTT broker can send a crafted MQTT message that deletes a specified slave (satellite) node from the local mesh management data and forces the system to reboot. The practical impact is disruption of mesh Wi-Fi service and corruption of mesh configuration (removal of nodes from management), an integrity and availability loss with no known path to code execution or data theft described in the advisory. Any T6 deployment on the affected firmware is in scope, with remote (internet-side) exploitability depending on whether the MQTT listener is reachable from the WAN rather than only the local network. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently assigns roughly a 0.4% probability of exploitation within 30 days.
What to do: Check the device's firmware version and, if it is 4.1.5cu.748_B20211015 (the only build named in the advisory), monitor TOTOLINK for a patched release, as no fixed version is specified yet. As an interim mitigation, restrict reachability of the cs_broker MQTT service (conventionally TCP 1883): do not expose it to the WAN and limit LAN-side access to trusted clients, since LAN access is sufficient to trigger the flaw. Administrators of multi-node mesh deployments should also review mesh management data for unexpectedly removed slave nodes and unexpected reboots as potential exploitation indicators.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local mesh management data and reboot the system via sending a crafted MQTT message to the cs_broker component.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.