Access Control Vulnerability in TOTOLINK T6 Device
CVE-2026-51748

5.9MEDIUM

Key Information:

Vendor

TOTOLINK

Vendor
CVE Published:
1 September 2026

What is CVE-2026-51748?

An access control vulnerability exists in the sendStaticInfoToMaster function of the TOTOLINK T6 device. This flaw enables unauthenticated attackers to craft and send MQTT messages that can alter stored slave inventory records. Malicious actors may exploit this vulnerability to compromise the integrity of device records without requiring appropriate authentication, posing a significant risk to system security.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.