Junglewise Threat Intelligence

CVE-2026-51744: TOTOLINK T6 incorrect access control in recv_mesh_info_sync

CVE-2026-51744 · Severity: critical · CVSS 9.8 · Published 2026-09-01

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a mesh-capable wireless router used in home and small business networks. A critical flaw in the mesh configuration synchronization function allows unauthenticated attackers to force the device to sync mesh settings from an attacker-controlled server by sending a specially crafted message. An attacker could hijack mesh network topology, redirect traffic, or inject malicious configurations across all connected mesh devices.

Technical details

The recv_mesh_info_sync function in the cs_broker component implements incorrect access control, failing to validate the source of mesh synchronization requests. The vulnerability is triggered by sending a crafted MQTT message to the cs_broker service, which processes the message without authentication verification. The attack is network-reachable if MQTT is accessible (either internally or externally), and does not require prior authentication or user interaction. A successful exploit enables an attacker to force mesh configuration updates from a malicious host, potentially compromising the entire mesh network. Patches addressing this authentication bypass are availability status currently unknown.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-09-01: disclosed

References