Incorrect Access Control in TOTOLINK T6 by TOTOLINK
CVE-2026-51770

9.8CRITICAL

Key Information:

Vendor

TOTOLINK

Vendor
CVE Published:
1 September 2026

What is CVE-2026-51770?

The TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 is susceptible to an access control vulnerability in its sendToMasterQosConfig function. This flaw allows unauthenticated attackers to manipulate Quality of Service (QoS) settings by transmitting specially crafted MQTT messages to the cs_broker component. As a result, attackers can potentially disrupt the system's performance and control traffic management configurations without proper authorization.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.