Access Control Flaw in TOTOLINK Router Model T6
CVE-2026-51764
9.8CRITICAL
What is CVE-2026-51764?
The TOTOLINK T6 router versions prior to 4.1.5cu.748_B20211015 are susceptible to an improper access control vulnerability. This issue lies within the recvSlaveCloudCheckStatus function, which fails to enforce proper authentication mechanisms. As a result, unauthorized attackers can exploit this flaw by sending specially crafted MQTT messages to the cs_broker component. This exploitation can lead to the overwriting of cloud-result tracking files, posing potential risks to system integrity and user data security.
