


Perceptive Security
SOC/SIEM Consultancy

Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP inter…
Published:
1 September 2026 at 00:00:00
Alert date:
2 September 2026 at 00:16:07
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
CVE-2026-51743 is an incorrect access control vulnerability in the guest_wifi_sync function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. Unauthenticated attackers can exploit this flaw by sending a crafted MQTT message to the cs_broker component. Successful exploitation allows attackers to disable guest virtual AP interfaces on the affected device. The vulnerability requires no authentication, lowering the barrier for exploitation significantly. TOTOLINK T6 is a consumer/SOHO router, making this a network infrastructure concern. The issue has been reported via GitHub-based CVE vendor coordination repositories. No patch information is explicitly mentioned in the article. The vulnerability was sourced from the NVD (National Vulnerability Database). Related references include TOTOLINK's official website and firmware download pages.
Technical details
Mitigation steps:
Affected products:
TOTOLINK T6 4.1.5cu.748_B20211015
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-51743
https://github.com/DarkBoulder/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md
https://github.com/ShengWu00/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md
https://www.totolink.net/
https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/190/ids/36.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
