The vulnerability description for CVE-2026-51757 directly identifies 'meshSlaveUpdate' as the vulnerable function. It specifies that this function, part of the TOTOLINK T6 4.1.5cu.748_B20211015 firmware, suffers from incorrect access control. This flaw permits unauthenticated attackers to initiate critical operations, such as firmware download or flashing, on slave devices by sending crafted MQTT messages to the 'cs_broker' component. Without access to the specific firmware code or patches, the analysis relies on the explicit details provided in the CVE description. The GitHub READMEs provided in the references list many other CVEs for the same product, but not CVE-2026-51757, nor do they contain specific code patches for any of the listed CVEs. Therefore, the primary source of information for this specific CVE remains its description.