Access Control Vulnerability in TOTOLINK T6 Allows Unauthorized Disconnection of Wireless Clients
CVE-2026-51763

9.8CRITICAL

Key Information:

Vendor

TOTOLINK

Vendor
CVE Published:
1 September 2026

What is CVE-2026-51763?

An access control vulnerability exists in the freeStaClient function of the TOTOLINK T6. This issue allows unauthenticated attackers to disconnect wireless clients by sending specially crafted MQTT messages to the cs_broker component. Exploitation of this vulnerability can disrupt network connectivity for affected wireless clients, potentially leading to unauthorized access or denial of service.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.