CVE-2026-51766: High severity TOTOLINK T6 vulnerability
Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mesh slaves via sending a crafted MQTT message to the csbroker component.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
TOTOLINK T6 devices running version 4.1.5cu.748_B20211015 are affected. A mesh master can also propagate reboot commands to its mesh slave devices.
What does an attacker need to exploit it?
The issue can be exploited without authentication by sending a crafted MQTT message to the cs_broker component. The described impact is rebooting the local device, with additional reboot fan-out from a mesh master to slaves.
What configuration increases the impact?
Devices configured as a mesh master have broader impact because reboot commands can be sent onward to mesh slaves. The provided information does not identify any other configuration prerequisite or mitigation.