ZeroHour

CVE-2026-51757

moderate

Unauthenticated MQTT flash-command flaw in TOTOLINK T6 mesh firmware

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51757 is an incorrect access control flaw (CWE-284) in the meshSlaveUpdate function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted MQTT message to the device's cs_broker component, causing the slave (satellite) node of the mesh network to start a firmware download or a flash workflow. Because the flash process can be triggered with no authentication or user interaction, an attacker who can reach the broker could potentially install attacker-supplied firmware and fully compromise the slave node, consistent with the 9.8 CVSS score. Affected users are those running the TOTOLINK T6 mesh Wi-Fi system on the listed firmware, where the cs_broker service is reachable from the local network or from the internet if remote management is exposed. There is currently no public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days, so no exploitation is known.

What to do: Check your T6 firmware version and upgrade as soon as TOTOLINK publishes a fixed release (no fixed version is listed in the available data, so monitor vendor advisories). Until then, keep the T6's management interface and MQTT/cs_broker service off the WAN (disable remote/WAN management) and restrict which clients can reach the device on the LAN, e.g., by separating guest and IoT traffic. Treat any slave node as potentially compromised if untrusted clients had network access, and re-flash it from a trusted image once a patch is available.

Affected
TOTOLINK T6 (mesh Wi-Fi system, cs_broker component / meshSlaveUpdate function)4.1.5cu.748_B20211015 (the only version named in the CVE description; other builds may also be affected but are unconfirmed)
Estimated exposure
moderateroughly 10,000–50,000 devices, mostly home mesh installations — TOTOLINK is a niche consumer brand, and public internet-wide scans typically show tens of thousands of exposed TOTOLINK devices across all models, so this single mesh model plausibly accounts for thousands to low tens of thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflow on the slave device via sending a crafted MQTT message to the cs_broker component.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.