CVE-2026-51744: TOTOLINK T6 vulnerability
Published Sep 1, 2026
·Updated
Incorrect access control in the recvmeshinfosync function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to force mesh configuration synchronization from an attacker-controlled host via sending a crafted MQTT message to the csbroker component.
Affected Software
1 affected component
TOTOLINK T6=4.1.5cu.748_B20211015
Event History
Sep 1, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:19 PM
Description
Frequently Asked Questions
1
What must an attacker be able to do to exploit this issue?
The attacker must be able to send a crafted MQTT message to the device's cs_broker component from an attacker-controlled host. No authentication is required.
2
Which deployments are exposed?
TOTOLINK T6 devices running firmware 4.1.5cu.748_B20211015 are identified as affected. The provided information does not state whether other firmware versions are affected.
3
What is the immediate impact of successful exploitation?
An unauthenticated attacker can force mesh configuration synchronization from an attacker-controlled host.