Junglewise Threat Intelligence

CVE-2026-51754: TOTOLINK T6 access control bypass in updateSlaveIpList

CVE-2026-51754 · Severity: critical · CVSS 9.8 · Published 2026-09-01

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 routers contain an unauthenticated access control flaw that allows an attacker to remotely modify the slave IP inventory state by sending a crafted MQTT message. An attacker can exploit this to compromise device configuration and potentially manipulate which devices are trusted by the router, disrupting network operations and enabling further attacks.

Technical details

The vulnerability is a missing authentication check in the updateSlaveIpList function of TOTOLINK T6firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated MQTT messages sent to the cs_broker component to directly modify slave IP inventory state without validating the caller's credentials. An attacker with network access to the device (or on the same network) can send a malicious MQTT message to alter the list of trusted slave IP addresses. This leads to arbitrary modification of device configuration state. A patch availability has not been indicated in the advisory.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-09-01: disclosed

References