Sceawere

Vulnerability Detail

CVE-2026-51752UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TOTOLINK T6 Improper Access Control

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
4h ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending a crafted MQTT message to the cs_broker component.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-01T14:17:35.877Z",
  "pubdate": "2026-09-01T14:17:35.877Z",
  "executiveSummary": "The TOTOLINK T6 router, specifically firmware version 4.1.5cu.748_B20211015, contains a critical access control vulnerability located within the staticInfoSend function.\nThis flaw allows unauthenticated remote attackers to trigger unauthorized static information reporting to a designated master node.\nThe vulnerability originates from a lack of sufficient authentication or authorization checks when processing messages via the cs_broker component.\nBy sending a maliciously crafted MQTT message, an attacker can coerce the device into transmitting sensitive system or device metadata to an external entity.\nThis represents a significant security risk, as it facilitates information disclosure and potentially assists in further reconnaissance or lateral movement within a network environment.\nThe vulnerability is exploitable by an unauthenticated attacker who has network reachability to the MQTT broker utilized by the device, requiring no prior system privileges.",
  "technicalDetails": "The vulnerability is localized in the staticInfoSend function, which is responsible for the transmission of device static configuration and telemetry data to a master controller or management server.\nThe root cause of this security defect is an improper access control implementation within the cs_broker component, which handles message routing for the device's management protocols.\nThe cs_broker fails to validate the origin or the authentication status of incoming MQTT payloads before passing them to internal functions like staticInfoSend.\nAttack flow begins with an attacker identifying the device's MQTT broker endpoint. The attacker then constructs a crafted MQTT message designed to trigger the staticInfoSend procedure.\nWhen the cs_broker receives this specially formatted message, it fails to perform a verification check, thereby allowing the staticInfoSend function to execute as if it were a legitimate internal management command.\nThe execution of the staticInfoSend function forces the TOTOLINK T6 device to collect local static information and transmit it over the network to the configured master node.\nBecause the function is invoked without authentication, the attacker can effectively manipulate the device into leaking internal configuration details that are otherwise restricted to administrative users.\nThe impact of this vulnerability includes unauthorized information disclosure, which could reveal details about the network topology, firmware identifiers, or device-specific configuration parameters.\nThe affected firmware version, 4.1.5cu.748_B20211015, demonstrates a failure in secure messaging design, specifically concerning the trust boundaries between the MQTT broker interface and internal administrative functions.\nExploitation requires the attacker to have network access to the MQTT broker port. Once the payload is delivered, the system processes the request immediately, resulting in the unwanted exfiltration of data to the master destination.\nThis type of improper access control effectively bypasses the expected security architecture, allowing an external actor to perform administrative operations via a side-channel protocol."
}
CVE-2026-51752: TOTOLINK T6 Improper Access Control (MEDIUM Severity, CVSS: 5.3) - Sceawere