CVE-2026-51765
Unauthenticated MQTT record injection in TOTOLINK T6 mesh firmware
CVE-2026-51765 is an incorrect access control flaw (CWE-284) in the recvIndirectMeshInfo function of the cs_broker component on the TOTOLINK T6 mesh router, firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted MQTT message to the cs_broker listener and insert or replace mesh neighbor records without any credentials. Depending on network placement of the MQTT service, this could let an attacker manipulate the device's view of its mesh topology, and the critical CVSS 9.8 score reflects potential for high-impact changes to confidentiality, integrity, and availability. Users running the named TOTOLINK T6 firmware are affected; the data documents this specific version and does not enumerate other firmware revisions. Exploitation has not been reported: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.4% probability of exploitation in the next 30 days.
What to do: Check any deployed TOTOLINK T6 units for firmware 4.1.5cu.748_B20211015 and monitor TOTOLINK's site for a patched firmware release before upgrading, since no fixed version is named in the available data. As an interim mitigation, restrict the device's MQTT/cs_broker listener so it is not reachable from the WAN (and limit it to trusted mesh nodes where possible). Keep the device off direct internet exposure until vendor guidance is available.
| TOTOLINK T6 mesh router | 4.1.5cu.748_B20211015 (version cited in the advisory; other firmware revisions may be affected but are not documented in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted MQTT message to the cs_broker component.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.