CVE-2026-51770
moderateIncorrect access control in TOTOLINK T6 lets attackers push QoS settings via MQTT
CVE-2026-51770 is an incorrect access-control flaw (CWE-284) in the sendToMasterQosConfig function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker who can reach the device's cs_broker MQTT component can send a crafted MQTT message that causes the T6 node to forward attacker-controlled QoS settings to the master unit in a mesh deployment. This allows unauthorized modification of QoS/traffic-shaping configuration on the master device without any credentials, and the 9.8 CVSS score indicates potentially high impact on confidentiality, integrity, and availability. Owners and operators of TOTOLINK T6 mesh nodes running the named firmware are affected, especially where the MQTT service is reachable from untrusted networks. No exploitation is currently known: there is no public PoC, the flaw is not in CISA KEV, and EPSS assigns a 0.4% probability of exploitation within 30 days (37th percentile).
What to do: Verify the running firmware on T6 nodes and upgrade to a fixed release from TOTOLINK when one is published (no fixed version is specified in the available data). Until then, do not expose the cs_broker MQTT service or remote management to the WAN, and restrict MQTT access with firewall rules. Monitor TOTOLINK advisories for confirmation of the full affected version range.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (only version cited in the advisory; whether other builds are affected is not stated) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS settings to the master via sending a crafted MQTT message to the cs_broker component..
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.