PatchSiren cyber security CVE debrief
CVE-2026-51751 TOTOLINK CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-01T14:17:35.667Z and has not been modified since then. CVE-2026-51751 is a critical vulnerability in the TOTOLINK T6 device, specifically affecting the delSlaveDevice function. This function has incorrect access control, allowing unauthenticated attackers to remove specified slave devices from local mesh management data and reboot the system by sending crafted MQTT messages to the cs_broker component. The vulnerability has a CVSS score of 9.8 and is considered critical. Organizations and individuals using TOTOLINK T6 devices should be aware of this critical vulnerability and take immediate action to assess their exposure and implement mitigations. Evidence is based on CVE and NVD records, and additional information may be available through source references.
- Vendor
- TOTOLINK
- Product
- T6
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-01
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-01
- Advisory updated
- 2026-09-03
Who should care
Organizations and individuals using TOTOLINK T6 devices should be aware of this critical vulnerability and take immediate action to assess their exposure and implement mitigations.
Technical summary
CVE-2026-51751 is a critical vulnerability in the TOTOLINK T6 device, specifically affecting the delSlaveDevice function. This function has incorrect access control, allowing unauthenticated attackers to remove specified slave devices from local mesh management data and reboot the system by sending crafted MQTT messages to the cs_broker component. The vulnerability has a CVSS score of 9.8 and is considered critical.
Defensive priority
TOTOLINK T6 devices are vulnerable to a critical access control issue in the delSlaveDevice function, allowing unauthenticated attackers to remove slave devices and reboot the system via crafted MQTT messages.
Recommended defensive actions
- Inventory and assess TOTOLINK T6 devices for exposure
- Restrict access to MQTT messaging components
- Implement compensating controls to detect and prevent unauthorized MQTT messages
- Monitor for suspicious device removal and system reboot activities
- Apply vendor patches or updates when available
Evidence notes
The CVE-2026-51751 record indicates a critical vulnerability in TOTOLINK T6 devices due to incorrect access control in the delSlaveDevice function. This allows unauthenticated attackers to remove specified slave devices from local mesh management data and reboot the system by sending crafted MQTT messages to the cs_broker component. Evidence is based on CVE and NVD records.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-51751 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-51751
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-51751 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-51751
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/DarkBoulder/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md
-
Source reference
Unverified legacy reference
URL: https://github.com/ShengWu00/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md
-
Source reference
Unverified legacy reference
URL: https://www.totolink.net/
-
Source reference
Unverified legacy reference
URL: https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/190/ids/36.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.