Access Control Flaw in TOTOLINK Product Exposes Vulnerability
CVE-2026-51751

9.8CRITICAL

Key Information:

Vendor

TOTOLINK

Vendor
CVE Published:
1 September 2026

What is CVE-2026-51751?

A flaw in the access control mechanism of the TOTOLINK T6 4.1.5cu.748_B20211015 allows attackers without authentication to exploit the delSlaveDevice function. This vulnerability enables malicious actors to craft MQTT messages that can remove designated slave devices from the local mesh management data and trigger a reboot of the system, disrupting service and compromising network integrity. Immediate remediation steps, including applying patches and monitoring for unusual activity, are advised to safeguard affected installations.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.