


Perceptive Security
SOC/SIEM Consultancy

Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a…
Published:
1 september 2026 om 00:00:00
Alert date:
1 september 2026 om 18:05:17
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
CVE-2026-51766 describes an incorrect access control vulnerability in the setDevReboot function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. Unauthenticated attackers can exploit this flaw by sending a crafted MQTT message to the cs_broker component to trigger a device reboot. On mesh network master devices, the attack can fan out reboot commands to all connected mesh slave devices, amplifying the impact. No authentication is required to exploit this vulnerability, making it trivially accessible to remote attackers. The vulnerability affects the MQTT-based communication layer of the device's management interface. Successful exploitation results in denial of service through forced reboots across the mesh network. The issue has been documented in vendor coordination repositories on GitHub. TOTOLINK has been notified and download resources are referenced on their official site. The vulnerability poses a significant risk to network availability in environments using TOTOLINK T6 mesh deployments.
Technical details
Mitigation steps:
Affected products:
TOTOLINK T6 4.1.5cu.748_B20211015
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-51766
https://github.com/DarkBoulder/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md
https://github.com/ShengWu00/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.md
https://www.totolink.net/
https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/190/ids/36.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
