CVE-2026-51754
nicheUnauthenticated MQTT access-control flaw in TOTOLINK T6 mesh router
TOTOLINK T6 mesh router firmware 4.1.5cu.748_B20211015 contains an incorrect access control flaw (CWE-284) in the updateSlaveIpList function, which maintains the inventory of slave (extender) unit IP addresses. An unauthenticated attacker can trigger it by sending a crafted MQTT message to the device's cs_broker component, requiring no credentials and no user interaction, only network reachability to that service. Successful abuse lets the attacker overwrite the slave IP inventory state, potentially corrupting master-to-extender coordination or misrepresenting which devices are part of the mesh; the 9.8 CVSS score reflects high potential confidentiality, integrity, and availability impact. Owners running the affected T6 build are affected, with remote exposure limited to units whose MQTT broker is reachable from outside the local network. No public proof-of-concept or in-the-wild exploitation is known, the flaw is not in CISA's KEV, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days.
What to do: No fixed version is available in the published data, so owners of T6 units on build 4.1.5cu.748_B20211015 should check TOTOLINK's support site for an updated firmware rather than assuming a patch exists. Until an update is available, avoid port-forwarding the device's MQTT broker port to the internet and restrict cs_broker reachability to trusted LAN segments. Check your firmware version on the router's administration page to confirm whether your unit runs the affected build.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (only this firmware build is confirmed affected; other builds unverified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state via sending a crafted MQTT message to the cs_broker component.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.