Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-51750: TOTOLINK T6 router lets anyone change mesh channel
CVE-2026-51750 · published 2 days ago
Summary
The router model TOTOLINK T6 (firmware version 4.1.5cu.748_B20211015) does not verify who is sending a command to change its primary mesh channel. An attacker on the same network could send a specially crafted message and force the router to switch channels, disrupting device connections. Apply the latest firmware update from the vendor or disable the mesh feature if it is not needed.
Original advisory text
Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channel via sending a crafted M...
Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channel via sending a crafted MQTT message to the cs_broker component.
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published1 Sep 2026
Updated2 Sep 2026
First seen1 Sep 2026
Monitor software like this
Free during beta