Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-51765: TOTOLINK T6 router lets unauthenticated users alter mesh connections
CVE-2026-51765 · published 2 days ago
Summary
The TOTOLINK T6 firmware version 4.1.5 allows anyone on the network to send a specially crafted MQTT message that changes the list of nearby mesh devices. This could let an attacker redirect traffic or disrupt network performance. Update the firmware to the latest version or apply the vendor's recommended patch as soon as possible.
Original advisory text
Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted ...
Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted MQTT message to the cs_broker component.
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published1 Sep 2026
Updated3 Sep 2026
First seen1 Sep 2026
Monitor software like this
Free during beta