← Terug naar overzicht

CVE-2026-51766 describes an incorrect access control vulnerability in the setDevReboot function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. Unauthenticated attackers can exploit this flaw by sending a crafted MQTT message to the cs_broker component to force a device reboot. In mesh network configurations, a compromised master device can propagate reboot commands to all slave nodes, amplifying the impact. The vulnerability requires no authentication, making it trivially exploitable remotely. This can result in denial of service across an entire mesh network. The issue has been documented via GitHub-based CVE vendor coordination repositories. TOTOLINK's official website and firmware download pages are referenced as part of the disclosure. No patch status is confirmed in the article content.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Related CVE's

  • CVE-2026-51766

Categories

  • Mobile & IoT
  • Network Infrastructure