VYPR
Published Sep 1, 2026· Updated Sep 2, 2026· 1 source

Totolink T6: 25 Access Control Flaws Disclosed Together on August 31/September 1, 2026

Key findings • 25 access control vulnerabilities disclosed in Totolink T6 firmware 4.1.5cu.748_B20211015. • Flaws primarily involve unauthenticated manipulation of MQTT messages and POST requ…

Key findings

  • 25 access control vulnerabilities disclosed in Totolink T6 firmware 4.1.5cu.748_B20211015.
  • Flaws primarily involve unauthenticated manipulation of MQTT messages and POST requests to the cs_broker and cgi-bin endpoints.
  • Vulnerabilities enable device reboots, QoS modification, mesh manipulation, and service termination.
  • Critical flaws include disabling guest Wi-Fi and terminating critical services (CVE-2026-51743, CVE-2026-51740).
  • All affected devices run firmware version 4.1.5cu.748_B20211015.

On August 31 and September 1, 2026, a coordinated disclosure event revealed 25 vulnerabilities affecting Totolink T6 routers running firmware version 4.1.5cu.748_B20211015. The majority of these flaws stem from incorrect access control within the device's cs_broker component, allowing unauthenticated attackers to send crafted MQTT messages to compromise various functionalities. A smaller subset of vulnerabilities targets the /cgi-bin/cstecgi.cgi endpoint, accepting crafted POST requests. These vulnerabilities collectively pose a significant risk to users, enabling actions ranging from device reboots and configuration manipulation to disabling critical security features.

Several vulnerabilities revolve around the manipulation of Quality of Service (QoS) settings and mesh network configurations. CVE-2026-51770, CVE-2026-51768, and CVE-2026-51766 allow attackers to forward attacker-controlled QoS settings, modify privileged QoS policies, and reboot local or mesh slave devices, respectively. Mesh network integrity is further threatened by CVE-2026-51765, which permits the insertion or replacement of mesh neighbor records, and CVE-2026-51763, enabling the forced disconnection of wireless clients. Additionally, CVE-2026-51757 and CVE-2026-51756 allow attackers to initiate firmware downloads or flashing on slave devices, potentially leading to the installation of malicious firmware.

Other critical functions are exposed through the cs_broker component. CVE-2026-51769 enables unauthenticated attackers to restart the cloud update check workflow, while CVE-2026-51764 allows overwriting cloud-result tracking files. The device's pairing state and reboot functionality can be manipulated via CVE-2026-51766 and CVE-2026-51767. Furthermore, CVE-2026-51750 and CVE-2026-51752 allow attackers to update slave inventory records and trigger static information reporting, respectively. The mesh configuration synchronization can be forced via CVE-2026-51744, and the primary station list can be refreshed using CVE-2026-51745.

The /cgi-bin/cstecgi.cgi endpoint is implicated in several high-impact vulnerabilities. CVE-2026-51740, a critical vulnerability with a CVSSv3 score of 9.8, allows unauthenticated attackers to terminate critical services by sending a crafted POST request to the killProcess function. Another critical vulnerability, CVE-2026-51743 (CVSSv3 9.1), enables the disabling of guest Wi-Fi interfaces. CVE-2026-51742 (CVSSv3 5.9) allows attackers to trigger WAN discovery logic, while CVE-2026-51741 permits the erasure of diagnosis logs.

The batch also includes vulnerabilities related to network configuration and management. CVE-2026-51761 (CVSSv3 5.3) allows attackers to refresh the LAN address state, and CVE-2026-51754 enables overwriting the slave IP inventory state. CVE-2026-51751 allows the removal of slave devices and system reboots, and CVE-2026-51750 enables updating stored slave inventory records. CVE-2026-51747 allows the emission of indirect mesh heartbeat information. CVE-2026-51748 permits updating stored slave inventory records. Finally, CVE-2026-51750 allows attackers to rescan and switch the primary mesh channel.

All 25 vulnerabilities affect Totolink T6 firmware version 4.1.5cu.748_B20211015. Users are strongly advised to consult Totolink's official advisories for specific patching instructions and mitigation strategies. Given the severity and breadth of these access control flaws, prompt patching is crucial to prevent potential compromise of network integrity and device control. The coordinated nature of this disclosure highlights the importance of timely security updates for all connected devices.

Synthesized by Vypr AI