Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-51769: TOTOLINK T6 router can be forced to restart cloud update
CVE-2026-51769 · published 2 days ago
Summary
The router model TOTOLINK T6 running version 4.1.5cu.748_B20211015 lets anyone send a specially crafted message to trigger a restart of its cloud update check. This could be used to disrupt update processes or cause unnecessary network traffic. Apply the latest firmware update from the vendor to fix the issue.
Original advisory text
Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to restart the cloud update check workflow via sending a crafte...
Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to restart the cloud update check workflow via sending a crafted MQTT message to the cs_broker component.
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published1 Sep 2026
Updated2 Sep 2026
First seen1 Sep 2026
Monitor software like this
Free during beta