Junglewise Threat Intelligence

CVE-2026-51763: TOTOLINK T6 freeStaClient access control bypass

CVE-2026-51763 · Severity: critical · CVSS 9.8 · Published 2026-09-01

Vendors: TOTOLINK.

Executive brief

The TOTOLINK T6 is a wireless router used to provide network connectivity to homes and offices. An unauthenticated attacker can send a specially crafted message to the device's internal messaging system to forcibly disconnect wireless clients from the network. This allows an attacker to disrupt network service for all connected devices without needing any legitimate access credentials.

Technical details

The vulnerability is an incorrect access control flaw in the freeStaClient function of the TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The vulnerable component fails to properly authenticate requests sent via MQTT messages to the cs_broker component. An unauthenticated attacker on the network can craft an MQTT message that triggers the freeStaClient function to disconnect arbitrary wireless clients from the router. No authentication or user interaction is required; network reachability to the device is sufficient. The attack results in denial of service to affected wireless clients.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-09-01: disclosed

References