Access Control Flaw in TOTOLINK Product Enables Unauthorized Firmware Upgrades
CVE-2026-51756
5.9MEDIUM
What is CVE-2026-51756?
A vulnerability exists in the TOTOLINK T6 (version 4.1.5cu.748_B20211015) due to inadequate access controls in the meshSlaveUpgfw function. This flaw enables unauthenticated attackers to initiate firmware flashing processes by sending specially crafted MQTT messages to the cs_broker component. If exploited, this could lead to unauthorized modifications of the device firmware, potentially compromising device integrity and user security.
