Access Control Flaw in TOTOLINK Device Impacts Unauthenticated Users
CVE-2026-51767
9.8CRITICAL
What is CVE-2026-51767?
An incorrect access control vulnerability exists in the recvClearPairCfg function of the TOTOLINK T6. This flaw enables unauthenticated attackers to manipulate the pairing state of the device and reboot it by sending malicious MQTT messages to the cs_broker component, posing significant security risks to users. Due to this vulnerability, unauthorized parties may gain control over device functionalities, potentially leading to further exploitation.
