Junglewise Threat Intelligence

CVE-2026-51745: TOTOLINK T6 updatePriStaList unauthenticated access control bypass

CVE-2026-51745 · Severity: medium · CVSS 5.3 · Published 2026-09-01

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a router device that manages connected devices and their network settings. This vulnerability allows an attacker to manipulate the primary station list without authentication by sending a crafted message to an internal component, potentially disrupting network operations or gaining unauthorized control over connected device management.

Technical details

The vulnerability is an incorrect access control flaw in the updatePriStaList function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The cs_broker component fails to properly validate credentials before processing requests to update the primary station list. An unauthenticated attacker on the network can exploit this by sending a crafted MQTT message to trigger unauthorized modifications of the primary station list. The attack requires network access to the device but does not require prior authentication. No patch information is currently available.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-09-01: disclosed

References