Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via sending a crafted MQTT message to the cs_broker component.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-51743 represents a critical access control failure in TOTOLINK T6 routers (version 4.1.5cu.748_B20211015) where the guest_wifi_sync function fails to properly authenticate MQTT message sources. This vulnerability allows unauthenticated attackers to disable guest virtual access point interfaces by sending specially crafted messages to the cs_broker component, effectively performing a denial-of-service attack against network guest functionality. The flaw is particularly concerning because MQTT is commonly used for IoT device management and inter-component communication, meaning attackers on the same network—or potentially remote attackers if MQTT is exposed—can manipulate critical network infrastructure without any credentials. Small office and home office (SOHO) environments relying on TOTOLINK routers for guest network isolation face immediate risk, as do organizations using these devices in edge deployments.
While this CVE lacks current MITRE ATT&CK mappings, Casky's 754 security skills enable Claude AI to detect the attack patterns underlying this vulnerability through extended reasoning across multiple security domains. Practitioners would observe findings related to CWE-284 (Improper Access Control) detection, including unauthenticated API/protocol interactions, unvalidated message processing in MQTT brokers, and privilege escalation through component manipulation. Casky's skill library would flag suspicious patterns such as: unauthenticated state-changing operations, guest network configuration modifications without authentication context, and anomalous MQTT publish events from unknown sources targeting the cs_broker. Security teams would see recommendations to monitor for T1562 (Impair Defenses) activities—specifically disabling or modifying guest access controls—and implement network segmentation isolating MQTT communication channels. The platform's reasoning engine would correlate these indicators with typical SOHO exploitation patterns, helping practitioners prioritize patching and implement compensating controls like MQTT authentication enforcement and network access restrictions.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-51743. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation