PatchSiren cyber security CVE debrief
CVE-2026-51764 TOTOLINK CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-01T14:17:36.873Z and has not been modified since then. The recvSlaveCloudCheckStatus function in TOTOLINK T6 4.1.5cu.748_B20211015 has incorrect access control, allowing unauthenticated attackers to overwrite cloud-result tracking files via a crafted MQTT message to the cs_broker component. This vulnerability has a CVSS score of 9.8 and is considered CRITICAL. Affected systems require immediate attention to prevent potential overwrites of cloud-result tracking files. Organizations using TOTOLINK T6 devices, cybersecurity teams, and network administrators should be aware of this critical vulnerability and take immediate action to verify and apply vendor remediation.
- Vendor
- TOTOLINK
- Product
- T6
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-01
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-01
- Advisory updated
- 2026-09-03
Who should care
Organizations using TOTOLINK T6 devices, cybersecurity teams, and network administrators should be aware of this critical vulnerability and take immediate action to verify and apply vendor remediation. Additionally, operators of affected platforms, vulnerability management teams, and security personnel responsible for monitoring and incident response should prioritize this vulnerability for remediation due to its high severity and potential impact on cloud-result tracking files.
Technical summary
The recvSlaveCloudCheckStatus function in TOTOLINK T6 4.1.5cu.748_B20211015 has incorrect access control, allowing unauthenticated attackers to overwrite cloud-result tracking files via a crafted MQTT message to the cs_broker component. This vulnerability has a CVSS score of 9.8 and is considered CRITICAL. Affected systems require immediate attention to prevent potential overwrites of cloud-result tracking files.
Defensive priority
TOTOLINK T6 devices require immediate attention due to a critical vulnerability allowing unauthenticated attackers to overwrite cloud-result tracking files.
Recommended defensive actions
- Verify and apply vendor remediation for TOTOLINK T6 4.1.5cu.748_B20211015
- Implement compensating controls to restrict access to cloud-result tracking files
- Monitor for suspicious MQTT messages to the cs_broker component
- Conduct inventory checks for affected TOTOLINK T6 devices
- Exception tracking for potential overwrites of cloud-result tracking files
Evidence notes
The recvSlaveCloudCheckStatus function in TOTOLINK T6 4.1.5cu.748_B20211015 is vulnerable to incorrect access control, allowing unauthenticated attackers to overwrite cloud-result tracking files via a crafted MQTT message to the cs_broker component. Evidence is limited; further verification is required. Additional review of MQTT message handling and cloud-result tracking file management is necessary to understand the full scope of this vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-51764 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-51764
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-51764 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-51764
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/DarkBoulder/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md
-
Source reference
Unverified legacy reference
URL: https://github.com/ShengWu00/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md
-
Source reference
Unverified legacy reference
URL: https://www.totolink.net/
-
Source reference
Unverified legacy reference
URL: https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/190/ids/36.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.