Description
Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message to the cs_broker component.
Published: 2026-09-01
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the freeStaClient function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015, where improper access control allows an attacker to send a specially crafted MQTT message to the cs_broker component and force a wireless client to disconnect. The effect is a disruption of the client’s network connectivity, leading to a denial of availability for the affected users without granting any other privileges or malicious code execution.

Affected Systems

The affected product is TOTOLINK’s T6 router running firmware 4.1.5cu.748_B20211015. No other vendors or product variants are currently listed. Users with this specific firmware should identify whether their device matches the version mentioned.

Risk and Exploitability

The CVE has a CVSS score of 9.8, an EPSS score of <1%, and is not listed in CISA’s KEV catalog, indicating a high severity but low probability of exploitation. However, the vulnerability is exploitable remotely via the MQTT service, which is commonly reachable on the device’s internal network or through exposed ports. An unauthenticated attacker can trigger a client disconnect with a single crafted packet, potentially impacting all users connected to the router. The lack of an official fix or workaround means that, until firmware is updated, the risk remains high for any environment where the vulnerable TOTOLINK router is in use.

Generated by OpenCVE AI on September 3, 2026 at 14:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update provided by TOTOLINK that addresses the freeStaClient access control issue.
  • If a firmware update is unavailable, restrict access to the MQTT broker by limiting it to trusted internal IP addresses or disabling it entirely if the feature is not required.
  • Use firewall rules or network segmentation to block external traffic on the MQTT port (default 1883) to prevent unauthorized message injection.

Generated by OpenCVE AI on September 3, 2026 at 14:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated MQTT Message Disconnection Allowing Forceful Wireless Client Logout in TOTOLINK T6

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated MQTT Message Disconnection Allowing Forceful Wireless Client Logout in TOTOLINK T6
First Time appeared Totolink
Totolink t6
Weaknesses CWE-284
Vendors & Products Totolink
Totolink t6

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message to the cs_broker component.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-02T16:26:10.695Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51763

cve-icon Vulnrichment

Updated: 2026-09-02T16:24:50.005Z

cve-icon NVD

Status : Deferred

Published: 2026-09-01T14:17:36.757

Modified: 2026-09-03T17:21:57.410

Link: CVE-2026-51763

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:00:06Z

Weaknesses