Junglewise Threat Intelligence

CVE-2026-51751: TOTOLINK T6 access control bypass in delSlaveDevice

CVE-2026-51751 · Severity: critical · CVSS 9.8 · Published 2026-09-01

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a mesh networking router used to extend wireless coverage in homes and offices. The device's mesh management system lacks proper authentication checks, allowing an attacker to send a crafted message to remove connected devices and force a system reboot without needing any credentials, potentially disrupting network operations and causing data loss.

Technical details

The vulnerability is an authentication bypass in the delSlaveDevice function within the cs_broker component of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can craft a malicious MQTT message and send it to the cs_broker component to remove a slave device from the mesh network's local management data and trigger a system reboot. The attack is network-accessible and requires no user interaction or credentials. The root cause is missing access control validation in the function, allowing any caller to invoke privileged operations.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-09-01: disclosed

References