CVE-2026-51768
largeIncorrect access control in TOTOLINK T6 allows unauthenticated QoS policy changes
CVE-2026-51768 is an incorrect access control flaw (CWE-284) in the setElinkQosConfig function of the cs_broker component on TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted MQTT message to the cs_broker component, which the device accepts without verifying that the sender is authorized. Successful exploitation allows the attacker to modify privileged QoS (Quality of Service) policy settings on the master device, an integrity-only impact with no confidentiality loss or denial of service per the CVSS 3.1 score. Users of TOTOLINK T6 devices on the affected firmware, particularly units whose MQTT broker can be reached from an untrusted network, are exposed. There are no reports of exploitation in the wild, no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns roughly a 0.3% probability of exploitation in the next 30 days.
What to do: Check your T6 firmware version and, since no fixed version is named in the advisory, watch TOTOLINK's support site for an updated firmware beyond 4.1.5cu.748_B20211015 and apply it when released. In the meantime, restrict the router's MQTT and management interfaces from untrusted networks (for example, disable WAN-side remote management if enabled) and watch QoS settings for unauthorized changes. No public exploit is known and EPSS is low, so this is a moderate-priority hardening item rather than an emergency.
| TOTOLINK T6 router (master device, cs_broker component) | 4.1.5cu.748_B20211015 (the firmware named in the advisory; no other version ranges or fixed version were provided) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setElinkQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify privileged QoS policy on the master device via sending a crafted MQTT message to the cs_broker component.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.