Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-51770: TOTOLINK T6 router lets anyone alter traffic settings

CVE-2026-51770 · published 2 days ago
Summary

The TOTOLINK T6 firmware version 4.1.5 allows people without a login to send specially crafted messages that change quality‑of‑service settings on the device. This could let an attacker prioritize or disrupt network traffic. Update the firmware to the latest version or apply the vendor’s recommended patch to restore proper access controls.

Original advisory text
Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS settings to the master via se...
Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS settings to the master via sending a crafted MQTT message to the cs_broker component..
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published1 Sep 2026
Updated2 Sep 2026
First seen1 Sep 2026
Sources
CVE-2026-51770 · MITRE
Monitor software like this
Free during beta