top of page
perceptive_background_267k.jpg

Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a…

Published:

1 september 2026 om 00:00:00

Alert date:

1 september 2026 om 18:05:17

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure

CVE-2026-51766 describes an incorrect access control vulnerability in the setDevReboot function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. Unauthenticated attackers can exploit this flaw by sending a crafted MQTT message to the cs_broker component to trigger a device reboot. On mesh network master devices, the attack can fan out reboot commands to all connected mesh slave devices, amplifying the impact. No authentication is required to exploit this vulnerability, making it trivially accessible to remote attackers. The vulnerability affects the MQTT-based communication layer of the device's management interface. Successful exploitation results in denial of service through forced reboots across the mesh network. The issue has been documented in vendor coordination repositories on GitHub. TOTOLINK has been notified and download resources are referenced on their official site. The vulnerability poses a significant risk to network availability in environments using TOTOLINK T6 mesh deployments.

Technical details

Mitigation steps:

Affected products:

TOTOLINK T6 4.1.5cu.748_B20211015

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page