Description
Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending a crafted MQTT message to the cs_broker component.
Published: 2026-09-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Exfiltration via Unauthenticated MQTT Access
Action: Patch Now
AI Analysis

Impact

This vulnerability arises from improper access control in the staticInfoSend function, enabling unauthenticated attackers to force the device to send static information to a preconfigured master server. The impact is the disclosure of device configuration and status data, which could be leveraged for further reconnaissance or targeted attacks but does not provide remote code execution or direct control over the device. The weakness is an authorization flaw that allows privileged data retrieval without authentication.

Affected Systems

The affected product is TOTOLINK T6 running firmware version 4.1.5cu.748_B20211015. No other vendors or product lines are listed.

Risk and Exploitability

CVE-2026-51752 has a CVSS score of 5.3 and no EPSS score, and it is not listed in the CISA KEV catalog, indicating no confirmed public exploitation yet. Nonetheless, based on the description, the likely attack vector is network-based and relies on sending a crafted MQTT message to the cs_broker component; any device with exposed MQTT bootstrap could be targeted. Given the potential for confidential data leakage and the ease of exploitation if the MQTT port is accessible, the risk should be considered moderate to high, especially in environments where device information may be sensitive.

Generated by OpenCVE AI on September 2, 2026 at 05:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update TOTOLINK T6 firmware to the latest patch that enforces proper authentication for the staticInfoSend endpoint.
  • If an immediate firmware update is unavailable, restrict inbound MQTT traffic to verified master controllers using firewall rules or VLAN segmentation.
  • Disable or remove the master reporting configuration from the device to prevent automated data exfiltration until a patch can be applied.

Generated by OpenCVE AI on September 2, 2026 at 05:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated MQTT Access Enables Static Info Exfiltration in TOTOLINK T6

Wed, 02 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Static Information Reporting via MQTT in TOTOLINK T6
Weaknesses CWE-285

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Static Information Reporting via MQTT in TOTOLINK T6
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
CWE-285
Vendors & Products Totolink
Totolink t6
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending a crafted MQTT message to the cs_broker component.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T15:45:21.521Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51752

cve-icon Vulnrichment

Updated: 2026-09-01T15:44:40.754Z

cve-icon NVD

Status : Deferred

Published: 2026-09-01T14:17:35.877

Modified: 2026-09-01T21:00:36.830

Link: CVE-2026-51752

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T05:15:05Z

Weaknesses