CVE-2026-51763
nicheUnauthenticated access-control flaw in TOTOLINK T6 allows forced Wi-Fi client disconnects
CVE-2026-51763 is an incorrect access control flaw (CWE-284) in the freeStaClient function of the cs_broker component in TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An unauthenticated attacker who can reach the router's MQTT broker can send a crafted MQTT message that triggers freeStaClient without proper authorization. Successful abuse allows the attacker to forcibly disconnect wireless clients from the router, degrading Wi-Fi availability; the published description describes no confidentiality or integrity compromise, despite the critical 9.8 CVSS 3.1 score. Only deployments of the TOTOLINK T6 running the named firmware version are reported as affected. There is no public proof-of-concept, the issue is not in CISA's KEV catalog, and the 0.4% EPSS (37th percentile) indicates low near-term exploitation probability.
What to do: Check whether your T6 runs firmware 4.1.5cu.748_B20211015 and monitor TOTOLINK's website or support channels for a corrected firmware release, as no fixed version is named in available reporting. In the meantime, limit reachability of the router's MQTT/cs_broker service — do not expose administrative or cloud-facing interfaces to the WAN and keep MQTT traffic confined to the trusted LAN. Given the described impact is limited to forced Wi-Fi client disconnects and EPSS is low, overall risk is low, but unauthenticated network access to the broker should be eliminated.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message to the cs_broker component.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.