Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS settings to the master via sending a crafted MQTT message to the cs_broker component..
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 02 Sep 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized QoS Configuration via MQTT in TOTOLINK T6 | |
| Weaknesses | CWE-285 |
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS settings to the master via sending a crafted MQTT message to the cs_broker component.. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-01T15:56:11.772Z
Reserved: 2026-06-08T00:00:00.000Z
Link: CVE-2026-51770
No data.
Status : Deferred
Published: 2026-09-01T16:17:05.177
Modified: 2026-09-01T21:00:36.830
Link: CVE-2026-51770
No data.
OpenCVE Enrichment
Updated: 2026-09-02T01:15:05Z
Weaknesses
No weakness.