Access Control Flaw in TOTOLINK Product Exposes Vulnerability
CVE-2026-51751
9.8CRITICAL
What is CVE-2026-51751?
A flaw in the access control mechanism of the TOTOLINK T6 4.1.5cu.748_B20211015 allows attackers without authentication to exploit the delSlaveDevice function. This vulnerability enables malicious actors to craft MQTT messages that can remove designated slave devices from the local mesh management data and trigger a reboot of the system, disrupting service and compromising network integrity. Immediate remediation steps, including applying patches and monitoring for unusual activity, are advised to safeguard affected installations.
