Junglewise Threat Intelligence

CVE-2026-51760: TOTOLINK T6 incorrect access control in informSyncUpgfw

CVE-2026-51760 · Severity: critical · CVSS 9.8 · Published 2026-09-01

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 mesh routers are used to provide wireless networking and device connectivity across homes and offices. An unauthenticated attacker can send a specially crafted MQTT message to trigger firmware update operations across all slave devices in a mesh network without authorization, causing service disruption and potential network-wide device instability.

Technical details

The vulnerability is an incorrect access control flaw in the informSyncUpgfw function of the cs_broker component in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The function fails to validate whether an MQTT message sender is authenticated before processing firmware update commands, allowing any network-adjacent or remote attacker with access to the MQTT broker to mass-trigger firmware synchronization across mesh slave devices. The attack requires crafting an MQTT message to the cs_broker, but no authentication credentials or user interaction are required. An attacker can exploit this to cause denial of service, force unexpected device reboots, or create opportunities for supply-chain attacks via malicious firmware. No patch information is currently available in the advisory.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-09-01: disclosed

References