Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-51760: TOTOLINK T6 routers let attackers force many firmware updates
CVE-2026-51760 · published 2 days ago
Summary
The TOTOLINK T6 access point (firmware version 4.1.5cu.748_B20211015) does not properly verify who can request a firmware upgrade. An unauthenticated person can send a crafted MQTT message that makes many mesh‑linked devices start updating at once, which could cause interruptions or install unwanted software. Install the vendor’s latest firmware and restrict MQTT traffic to trusted sources to mitigate the risk.
Original advisory text
Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity across mesh slaves via sendin...
Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity across mesh slaves via sending a crafted MQTT message to the cs_broker component.
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published1 Sep 2026
Updated3 Sep 2026
First seen1 Sep 2026
Monitor software like this
Free during beta