Access Control Flaw in TOTOLINK Product Enables Unauthorized Firmware Upgrades
CVE-2026-51756

5.9MEDIUM

Key Information:

Vendor

TOTOLINK

Vendor
CVE Published:
1 September 2026

What is CVE-2026-51756?

A vulnerability exists in the TOTOLINK T6 (version 4.1.5cu.748_B20211015) due to inadequate access controls in the meshSlaveUpgfw function. This flaw enables unauthenticated attackers to initiate firmware flashing processes by sending specially crafted MQTT messages to the cs_broker component. If exploited, this could lead to unauthorized modifications of the device firmware, potentially compromising device integrity and user security.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.