ZeroHour

CVE-2026-51762

moderate

Unauthenticated Access-Control Flaw in TOTOLINK T6 Mesh Router MQTT Component

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51762 is an incorrect access-control flaw (CWE-284) in the meshInfoKick function of the cs_broker component in TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An unauthenticated attacker on the network can send a crafted MQTT message to the cs_broker component, requiring no credentials or user interaction. This lets the attacker kick or clear stale mesh information and state and trigger regeneration of mesh metadata, potentially disrupting the mesh network's state; the assigned CVSS 3.1 score of 9.8 (critical) rates confidentiality, integrity, and availability impact as high. Only TOTOLINK T6 devices running the listed firmware build are identified as affected in the current data. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS currently estimates roughly a 0.4% chance of exploitation within 30 days.

What to do: Check TOTOLINK T6 units for firmware 4.1.5cu.748_B20211015 and upgrade to a corrected firmware from TOTOLINK when available, as no fixed version is specified in the current data. As an interim mitigation, restrict access to the device's MQTT broker (cs_broker) so it is not reachable from untrusted networks or the WAN. Given no public PoC, no KEV listing, and low EPSS, treat this as a moderate patching priority but monitor TOTOLINK advisories for a firmware release.

Affected
TOTOLINK T64.1.5cu.748_B20211015
Estimated exposure
moderatelikely thousands of T6 consumer mesh units worldwide (est.; no public install-base or scan counts exist for this specific model) — No public active-install or internet-exposure counts exist for the T6 specifically, so the order of magnitude is inferred from TOTOLINK's deployment pattern as a budget consumer router brand sold mainly in Asia and the Middle East, where…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of mesh metadata via sending a crafted MQTT message to the cs_broker component.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.