Junglewise Threat Intelligence

CVE-2026-51769: TOTOLINK T6 incorrect access control in remoteCloudUpdateCheck

CVE-2026-51769 · Severity: critical · CVSS 9.8 · Published 2026-09-01

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 is a home wireless router. An unauthenticated attacker can send a malicious message to a cloud update component to restart the cloud update workflow, potentially enabling firmware manipulation, service disruption, or unauthorized system changes on the router.

Technical details

The remoteCloudUpdateCheck function in the cs_broker component of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 lacks proper authentication checks. An unauthenticated attacker can craft a malicious MQTT message and send it to the cs_broker component to trigger a cloud update check workflow. The vulnerability is a classic missing authentication / incorrect access control flaw in a network-accessible service, allowing unauthenticated remote manipulation of a sensitive update mechanism. No patch information is currently available.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-09-01: disclosed

References