CVE-2026-51762: Critical severity TOTOLINK T6 vulnerability
Published Sep 1, 2026
·Updated
Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of mesh metadata via sending a crafted MQTT message to the csbroker component.
Affected Software
1 affected component
TOTOLINK T6=4.1.5cu.748_B20211015
Event History
Sep 1, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Devices running TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 are identified as affected. Exposure requires the cs_broker component to accept the crafted MQTT message used to reach meshInfoKick.
2
What does an attacker need to exploit it?
The attacker does not need authentication. They need the ability to send a crafted MQTT message to the device's cs_broker component.
3
What can an attacker do after exploitation?
An attacker can kick or clean stale mesh information or state and trigger regeneration of mesh metadata.