Access Control Flaw in TOTOLINK Router Product
CVE-2026-51762
9.8CRITICAL
What is CVE-2026-51762?
A vulnerability exists in TOTOLINK T6 routers due to incorrect access control in the meshInfoKick function. This flaw allows unauthenticated attackers to exploit the cs_broker component by sending specially crafted MQTT messages. Successful exploitation enables attackers to manipulate and clear mesh state information, leading to unwanted changes in mesh metadata and disrupting network operations.
