Access Control Flaw in TOTOLINK T6 Router
CVE-2026-51747
9.8CRITICAL
What is CVE-2026-51747?
An improper access control issue exists in the keepAlive function of the TOTOLINK T6 router, specifically in version 4.1.5cu.748_B20211015. This vulnerability allows unauthenticated attackers to send specially crafted MQTT messages to the cs_broker component, potentially emitting unauthorized indirect mesh heartbeat information to the master. This flaw emphasizes the importance of robust access controls to protect against unauthorized information disclosure.
