Access Control Vulnerability in TOTOLINK T6 Allows Unauthorized Disconnection of Wireless Clients
CVE-2026-51763
9.8CRITICAL
What is CVE-2026-51763?
An access control vulnerability exists in the freeStaClient function of the TOTOLINK T6. This issue allows unauthenticated attackers to disconnect wireless clients by sending specially crafted MQTT messages to the cs_broker component. Exploitation of this vulnerability can disrupt network connectivity for affected wireless clients, potentially leading to unauthorized access or denial of service.
