Access Control Flaw in TOTOLINK Router Software
CVE-2026-51757
9.8CRITICAL
What is CVE-2026-51757?
An access control vulnerability in the meshSlaveUpdate function of the TOTOLINK T6 version 4.1.5cu.748_B20211015 allows unauthorized users to initiate a firmware download or flash process. This exploitation occurs through the transmission of specially crafted MQTT messages directed at the cs_broker component, posing significant risks to system integrity and user data.
