Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronization from an attacker-controlled host via sending a crafted MQTT message to the cs_broker component.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-51744 is a critical access control flaw in TOTOLINK T6 routers (version 4.1.5cu.748_B20211015) that allows unauthenticated attackers to manipulate mesh network configurations through malicious MQTT messages. The vulnerability exists in the recv_mesh_info_sync function, which fails to validate the origin and legitimacy of incoming synchronization requests on the cs_broker component. This affects home and small office networks relying on mesh topology, enabling attackers to remotely inject malicious configurations, potentially compromising network integrity, data interception, and lateral movement into connected devices without requiring valid credentials.
While this CVE currently maps to zero Casky skills due to its nascent nature and missing MITRE ATT&CK alignment, practitioners using Casky's Claude-powered analysis would benefit from extended reasoning capabilities applied to related techniques like T1190 (Exploit Public-Facing Application), T1566 (Phishing), and T1021 (Remote Services). Security teams monitoring MQTT traffic patterns, unauthenticated network service access, and configuration tampering would receive AI-assisted anomaly detection identifying suspicious synchronization requests originating from untrusted sources. As threat intelligence matures and this CVE is mapped to specific techniques, Casky will surface relevant skills enabling practitioners to detect unauthorized mesh reconfiguration attempts, validate MQTT message authenticity, and isolate compromised nodes before attackers establish persistent network access.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-51744. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation