Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-51751: TOTOLINK T6 firmware lets remote attackers delete devices and reboot
CVE-2026-51751 · published 2 days ago
Summary
The current TOTOLINK T6 router software can be tricked into removing a mesh device and restarting the whole system without any login. This could let someone outside your network disrupt your Wi‑Fi coverage or cause temporary outages. Apply the latest firmware update from TOTOLINK or block unauthorized MQTT traffic to stop the issue.
Original advisory text
Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local mesh management data and ...
Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local mesh management data and reboot the system via sending a crafted MQTT message to the cs_broker component.
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published1 Sep 2026
Updated3 Sep 2026
First seen1 Sep 2026
Monitor software like this
Free during beta