PatchSiren cyber security CVE debrief
CVE-2026-51762 TOTOLINK CVE debrief
CVE-2026-51762 is a critical vulnerability in the TOTOLINK T6 4.1.5cu.748_B20211015 meshInfoKick function, allowing unauthenticated attackers to manipulate mesh information/state via crafted MQTT messages to cs_broker. This vulnerability has a CVSS score of 9.8 and is considered CRITICAL. Network administrators and security teams should be aware of this vulnerability and take steps to mitigate it. The CVE record was published on 2026-09-01T14:17:36.640Z and has not been modified since then. Evidence is limited; further verification is recommended.
- Vendor
- TOTOLINK
- Product
- T6
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-01
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-01
- Advisory updated
- 2026-09-03
Who should care
Network administrators and security teams responsible for TOTOLINK T6 devices, particularly those using version 4.1.5cu.748_B20211015, should be aware of this vulnerability and take steps to mitigate it. They should review device configurations, ensure proper access controls are in place, and monitor for potential exploitation attempts. Additionally, security teams should consider upgrading to a patched version if available and track exceptions and retest remediated assets to ensure the vulnerability is properly addressed. Operators of affected platforms and those responsible for vulnerability management should prioritize this issue due to its critical severity and potential impact on network security. Security teams should also verify the integrity of mesh information and state, and be prepared to respond to potential incidents related to this vulnerability. This requires coordination with affected vendors and potentially impacted stakeholders to ensure comprehensive mitigation and remediation efforts. Those responsible for asset inventory and change management should also be aware of the potential for exploitation and plan accordingly to minimize operational impact. The critical nature of this vulnerability necessitates prompt attention and action from all relevant parties to prevent potential security breaches. Security teams should also consider compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review. Finally, they should track exceptions, retest remediated assets, and close the item only after evidence is documented, ensuring that all necessary steps are taken to address this critical vulnerability effectively. Those managing change windows and rollback processes should be prepared to act swiftly to minimize exposure and ensure the security of their networks. In summary, a broad range of stakeholders, from network administrators to security teams and vulnerability management professionals, should be aware of this vulnerability and take proactive steps to mitigate its risks effectively. This includes not only immediate remediation but
Technical summary
The meshInfoKick function in TOTOLINK T6 4.1.5cu.748_B20211015 has incorrect access control, allowing unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of mesh metadata via sending a crafted MQTT message to the cs_broker component. This vulnerability has a CVSS score of 9.8 and is considered CRITICAL. The affected product is TOTOLINK T6 version 4.1.5cu.748_B20211015. Defensive measures include verifying device configurations, restricting MQTT message access, and monitoring for suspicious activity.
Defensive priority
TOTOLINK T6 4.1.5cu.748_B20211015 meshInfoKick function access control vulnerability allows unauthenticated attackers to manipulate mesh information/state via crafted MQTT messages to cs_broker.
Recommended defensive actions
- Verify TOTOLINK T6 4.1.5cu.748_B20211015 devices for potential mesh information/state manipulation
- Restrict MQTT message access to cs_broker component
- Monitor for suspicious MQTT activity
- Consider upgrading to a patched version if available
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
CVE-2026-51762 details are based on NVD and CVE Program records. The meshInfoKick function in TOTOLINK T6 4.1.5cu.748_B20211015 has incorrect access control, allowing unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of mesh metadata via crafted MQTT messages to cs_broker. Evidence is limited; further verification is recommended.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-51762 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-51762
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-51762 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-51762
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/DarkBoulder/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md
-
Source reference
Unverified legacy reference
URL: https://github.com/ShengWu00/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md
-
Source reference
Unverified legacy reference
URL: https://www.totolink.net/
-
Source reference
Unverified legacy reference
URL: https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/190/ids/36.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.