SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-51756

MEDIUM · CVSS 5.9 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability in the meshSlaveUpgfw function of TOTOLINK T6 allows unauthenticated attackers to initiate firmware flashing by sending a specially crafted MQTT message to the cs_broker component, potentially leading to unauthorized firmware modifications. This could compromise the integrity and security of the device, making it a critical concern for users and administrators of affected TOTOLINK products. Organizations utilizing these devices should prioritize patching or mitigating this vulnerability to prevent exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-51756
Severity
MEDIUM
CVSS
5.9
EPSS
0.34%

Original NVD Description

Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a crafted MQTT message to the cs_broker component.