ZeroHour

CVE-2026-51763

niche

Unauthenticated access-control flaw in TOTOLINK T6 allows forced Wi-Fi client disconnects

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51763 is an incorrect access control flaw (CWE-284) in the freeStaClient function of the cs_broker component in TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. An unauthenticated attacker who can reach the router's MQTT broker can send a crafted MQTT message that triggers freeStaClient without proper authorization. Successful abuse allows the attacker to forcibly disconnect wireless clients from the router, degrading Wi-Fi availability; the published description describes no confidentiality or integrity compromise, despite the critical 9.8 CVSS 3.1 score. Only deployments of the TOTOLINK T6 running the named firmware version are reported as affected. There is no public proof-of-concept, the issue is not in CISA's KEV catalog, and the 0.4% EPSS (37th percentile) indicates low near-term exploitation probability.

What to do: Check whether your T6 runs firmware 4.1.5cu.748_B20211015 and monitor TOTOLINK's website or support channels for a corrected firmware release, as no fixed version is named in available reporting. In the meantime, limit reachability of the router's MQTT/cs_broker service — do not expose administrative or cloud-facing interfaces to the WAN and keep MQTT traffic confined to the trusted LAN. Given the described impact is limited to forced Wi-Fi client disconnects and EPSS is low, overall risk is low, but unauthenticated network access to the broker should be eliminated.

Affected
TOTOLINK T64.1.5cu.748_B20211015
Estimated exposure
nichelikely on the order of thousands of T6 routers deployed worldwide (single consumer model) — No install counts are published for this model; the estimate reflects TOTOLINK's footprint as a budget consumer router vendor — public internet-wide scans have historically shown tens of thousands of TOTOLINK devices exposed, and the T6 is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message to the cs_broker component.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.