Access Control Vulnerability in TOTOLINK Router Products
CVE-2026-51754
9.8CRITICAL
What is CVE-2026-51754?
An access control issue in the updateSlaveIpList function of TOTOLINK T6 allows unauthenticated users to overwrite the slave IP inventory state. By sending specially crafted MQTT messages to the cs_broker component, attackers can exploit this vulnerability, leading to potential unauthorized network configurations and data exposure.
