Impact
This vulnerability arises from improper access control in the staticInfoSend function, enabling unauthenticated attackers to force the device to send static information to a preconfigured master server. The impact is the disclosure of device configuration and status data, which could be leveraged for further reconnaissance or targeted attacks but does not provide remote code execution or direct control over the device. The weakness is an authorization flaw that allows privileged data retrieval without authentication.
Affected Systems
The affected product is TOTOLINK T6 running firmware version 4.1.5cu.748_B20211015. No other vendors or product lines are listed.
Risk and Exploitability
CVE-2026-51752 has a CVSS score of 5.3 and no EPSS score, and it is not listed in the CISA KEV catalog, indicating no confirmed public exploitation yet. Nonetheless, based on the description, the likely attack vector is network-based and relies on sending a crafted MQTT message to the cs_broker component; any device with exposed MQTT bootstrap could be targeted. Given the potential for confidential data leakage and the ease of exploitation if the MQTT port is accessible, the risk should be considered moderate to high, especially in environments where device information may be sensitive.
OpenCVE Enrichment