Junglewise Threat Intelligence

CVE-2026-51761: TOTOLINK T6 authentication bypass in updateLanIp via MQTT

CVE-2026-51761 · Severity: medium · CVSS 5.3 · Published 2026-09-01

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a router that manages network configuration. An unauthenticated attacker can send a crafted MQTT message to modify the device's LAN IP address settings without providing login credentials, potentially disrupting network connectivity or facilitating further attacks on the device or connected network.

Technical details

The updateLanIp function in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 lacks proper access control checks, allowing unauthenticated MQTT messages to trigger changes to LAN configuration. The vulnerability exists in the cs_broker component, which processes incoming MQTT messages. An attacker with network access to the MQTT interface can send a crafted message to modify LAN IP settings without authentication. This represents a missing authentication vulnerability in the MQTT message handling code path.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-09-01: disclosed

References