


Perceptive Security
SOC/SIEM Consultancy

Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP inter…
Published:
1 September 2026 at 00:00:00
Alert date:
1 September 2026 at 21:01:21
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
CVE-2026-51743 describes an incorrect access control vulnerability in the guest_wifi_sync function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to disable guest virtual AP interfaces by sending a specially crafted MQTT message to the cs_broker component. No authentication is required to exploit this vulnerability, making it accessible to any attacker with network access to the device. The impact includes disruption of guest wireless network services. The vulnerability was reported via GitHub-based CVE vendor coordination repositories. TOTOLINK's official website and firmware download pages are referenced as part of the disclosure. This affects a consumer/SOHO IoT networking device, raising concerns about wide exposure in home and small business environments.
Technical details
Mitigation steps:
Affected products:
TOTOLINK T6 4.1.5cu.748_B20211015
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-51743
https://github.com/DarkBoulder/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md
https://github.com/ShengWu00/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md
https://www.totolink.net/
https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/190/ids/36.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
