ZeroHour

CVE-2026-51760

Unauthenticated access-control flaw in TOTOLINK T6 triggers mass mesh firmware updates

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51760 is an incorrect access control flaw (CWE-284) in the informSyncUpgfw function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. Because this function does not require authentication, an unauthenticated attacker can send a crafted MQTT message to the cs_broker component and cause firmware update activity to be triggered across all mesh slave nodes at once. An attacker gains the ability to force coordinated firmware-update states on the mesh network, and the critical 9.8 CVSS score (high confidentiality, integrity and availability impact) suggests significant potential downstream impact, although no public proof-of-concept documents a concrete abuse chain. Affected parties are anyone operating a TOTOLINK T6 mesh system on the listed firmware version. No exploitation has been reported: the flaw is not in CISA KEV, no public PoC exists, and EPSS estimates only a 0.4% probability of exploitation within 30 days.

What to do: Identify any TOTOLINK T6 units running firmware 4.1.5cu.748_B20211015 and apply TOTOLINK's patched firmware once a fixed release is published (no fixed version is documented yet). As an interim mitigation, prevent untrusted networks from reaching the device's MQTT/cs_broker service — do not expose it to the WAN and restrict LAN-side MQTT access to trusted clients. Monitor the mesh for coordinated firmware-update activity that was not initiated by an administrator.

Affected
TOTOLINK T64.1.5cu.748_B20211015
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity across mesh slaves via sending a crafted MQTT message to the cs_broker component.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.