Junglewise Threat Intelligence

CVE-2026-51750: TOTOLINK T6 incorrect access control in updatePriChannel

CVE-2026-51750 · Severity: critical · CVSS 9.8 · Published 2026-09-01

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a mesh Wi-Fi router system used to extend wireless network coverage. An unauthenticated attacker can send a specially crafted MQTT message to reconfigure the device's primary mesh channel without any authentication, potentially disrupting network connectivity and causing service outages for all connected devices.

Technical details

The vulnerability is an incorrect access control flaw in the updatePriChannel function of the cs_broker component. The function fails to validate the authenticity of MQTT messages before processing channel reconfiguration commands, allowing any network-adjacent attacker to send crafted MQTT messages and modify the primary mesh channel. This is a design-level auth bypass that affects the MQTT message broker interface. An attacker with network access to the device can change wireless channel settings without authentication, leading to network disruption and potential denial of service.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-09-01: disclosed

References