CVE-2026-51762
moderateUnauthenticated Access-Control Flaw in TOTOLINK T6 Mesh Router MQTT Component
CVE-2026-51762 is an incorrect access-control flaw (CWE-284) in the meshInfoKick function of the cs_broker component in TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An unauthenticated attacker on the network can send a crafted MQTT message to the cs_broker component, requiring no credentials or user interaction. This lets the attacker kick or clear stale mesh information and state and trigger regeneration of mesh metadata, potentially disrupting the mesh network's state; the assigned CVSS 3.1 score of 9.8 (critical) rates confidentiality, integrity, and availability impact as high. Only TOTOLINK T6 devices running the listed firmware build are identified as affected in the current data. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS currently estimates roughly a 0.4% chance of exploitation within 30 days.
What to do: Check TOTOLINK T6 units for firmware 4.1.5cu.748_B20211015 and upgrade to a corrected firmware from TOTOLINK when available, as no fixed version is specified in the current data. As an interim mitigation, restrict access to the device's MQTT broker (cs_broker) so it is not reachable from untrusted networks or the WAN. Given no public PoC, no KEV listing, and low EPSS, treat this as a moderate patching priority but monitor TOTOLINK advisories for a firmware release.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of mesh metadata via sending a crafted MQTT message to the cs_broker component.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.