Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pairing state and reboot the device via sending a crafted MQTT message to the cs_broker component.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 02 Sep 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated MQTT Reset Exploit in TOTOLINK T6 Device | |
| Weaknesses | CWE-269 CWE-284 |
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pairing state and reboot the device via sending a crafted MQTT message to the cs_broker component. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-01T15:53:46.476Z
Reserved: 2026-06-08T00:00:00.000Z
Link: CVE-2026-51767
No data.
Status : Deferred
Published: 2026-09-01T16:17:04.823
Modified: 2026-09-01T21:00:36.830
Link: CVE-2026-51767
No data.
OpenCVE Enrichment
Updated: 2026-09-02T01:30:20Z