Junglewise Threat Intelligence

CVE-2026-51752: TOTOLINK T6 incorrect access control in staticInfoSend

CVE-2026-51752 · Severity: medium · CVSS 5.3 · Published 2026-09-01

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a wireless mesh router used to provide network connectivity and remote management capabilities. An unauthenticated attacker can trigger unintended reporting of static device information to a remote master server by sending a specially crafted MQTT message, potentially exposing device configuration details and disrupting normal device operation.

Technical details

This is an incorrect access control vulnerability in the staticInfoSend function of the cs_broker component in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The vulnerability allows an unauthenticated attacker to craft and send a malicious MQTT message to the cs_broker component without authentication, triggering the staticInfoSend function to report static information to a configured master device. The attack requires network access to the device and MQTT connectivity but no authentication credentials. An attacker can leverage this to exfiltrate device configuration or disrupt device management operations. No public patch information is currently available.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-09-01: disclosed

References