CVE-2026-51611

TOTOLINK · T6

A critical access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to trigger an arbitrary device reboot via a crafted MQTT message.

Executive summary

A critical vulnerability in the TOTOLINK T6 allows unauthenticated remote attackers to force a system reboot, leading to potential denial of service and operational disruption.

Vulnerability

The device contains an incorrect access control flaw within the startSlaveReboot function. This permits an unauthenticated attacker to send a specially crafted MQTT message to the device to execute an unauthorized reboot.

Business impact

The ability for an unauthenticated remote actor to force a device reboot creates a significant denial of service risk. Because the device is an edge networking component, successful exploitation could result in widespread network outages, loss of connectivity for connected clients, and potential disruption to critical business operations. With a CVSS score of 9.8, this vulnerability represents a severe threat to infrastructure availability.

Remediation

Immediate Action: Users should immediately review the official TOTOLINK support portal for firmware updates addressing this flaw. If no patch is currently available, prioritize isolating the management interface from the public internet.

Proactive Monitoring: Monitor network traffic for anomalous MQTT protocol activity originating from untrusted sources. Review device logs for unexpected reboot events that occur without administrative intervention.

Compensating Controls: Implement firewall rules to restrict access to MQTT ports (typically 1883 or 8883) to authorized internal IP addresses only. Disable MQTT functionality on the device if it is not required for production operations.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical severity and the potential for remote denial of service, administrators must treat this vulnerability with high priority. We recommend restricting network access to the device immediately and verifying firmware status through the vendor portal. Apply all available security updates as soon as they are released to restore system integrity and operational reliability.

More TOTOLINK CVEs

Sources