← Back to overview

CVE-2026-51766 describes an incorrect access control vulnerability in the setDevReboot function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. Unauthenticated attackers can exploit this flaw by sending a crafted MQTT message to the cs_broker component to trigger a device reboot. On mesh network master devices, the attack can fan out reboot commands to all connected mesh slave devices, amplifying the impact. No authentication is required to exploit this vulnerability, making it trivially accessible to remote attackers. The vulnerability affects the MQTT-based communication layer of the device's management interface. Successful exploitation results in denial of service through forced reboots across the mesh network. The issue has been documented in vendor coordination repositories on GitHub. TOTOLINK has been notified and download resources are referenced on their official site. The vulnerability poses a significant risk to network availability in environments using TOTOLINK T6 mesh deployments.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Related CVE's

  • CVE-2026-51766

Categories

  • Mobile & IoT
  • Network Infrastructure