Access Control Vulnerability in TOTOLINK T6 Device
CVE-2026-51748
5.9MEDIUM
What is CVE-2026-51748?
An access control vulnerability exists in the sendStaticInfoToMaster function of the TOTOLINK T6 device. This flaw enables unauthenticated attackers to craft and send MQTT messages that can alter stored slave inventory records. Malicious actors may exploit this vulnerability to compromise the integrity of device records without requiring appropriate authentication, posing a significant risk to system security.
