Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-51764: TOTOLINK T6 router firmware can let outsiders replace cloud files

CVE-2026-51764 · published 2 days ago
Summary

The TOTOLINK T6 router running version 4.1.5cu.748_B20211015 has a weakness that does not require a login before it accepts certain messages. An attacker could send a specially crafted message through the router’s internal message system and overwrite files that record cloud‑service results, potentially disrupting or tampering with cloud communication. Install the latest firmware or any patches from TOTOLINK and restrict outside access to the router’s management interfaces.

Original advisory text
Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking files via sending a craft...
Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking files via sending a crafted MQTT message to the cs_broker component.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published1 Sep 2026
Updated2 Sep 2026
First seen1 Sep 2026
Sources
CVE-2026-51764 · MITRE
Monitor software like this
Free during beta