CVE-2026-51762: TOTOLINK T6 vulnerability
Published Sep 1, 2026
·Updated
Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of mesh metadata via sending a crafted MQTT message to the csbroker component.
Affected Software
1 affected component
TOTOLINK T6=4.1.5cu.748_B20211015
Event History
Sep 1, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:17 PM
Description
Frequently Asked Questions
1
Who is exposed to this issue?
Devices running TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 are identified as affected. Exposure requires the cs_broker component to accept the crafted MQTT message used to reach meshInfoKick.
2
What does an attacker need to exploit it?
The attacker does not need authentication. They need the ability to send a crafted MQTT message to the device's cs_broker component.
3
What can an attacker do after exploitation?
An attacker can kick or clean stale mesh information or state and trigger regeneration of mesh metadata.