CVE-2026-51743

9.1

TOTOLINK · T6

An access control flaw in the TOTOLINK T6 guest_wifi_sync function allows unauthenticated attackers to disable guest virtual AP interfaces using crafted MQTT messages.

Executive summary

A critical access control vulnerability in the TOTOLINK T6 router enables unauthenticated attackers to remotely disrupt guest network connectivity.

Vulnerability

This is an improper access control vulnerability located in the guest_wifi_sync function. An unauthenticated attacker can send a malicious MQTT message to the cs_broker component to disable guest virtual access points.

Business impact

The ability for an unauthenticated attacker to remotely disable network interfaces poses a significant risk to service availability and operational continuity. Given the CVSS score of 9.1, this vulnerability indicates a high potential for unauthorized administrative control over network settings, which could be leveraged to disrupt business operations or facilitate further network compromise.

Remediation

Immediate Action: Monitor vendor communication channels for a firmware update that addresses the guest_wifi_sync access control issue. If an update is not available, isolate the cs_broker component or disable guest Wi-Fi features until a patch is released.

Proactive Monitoring: Review network traffic logs for suspicious or malformed MQTT messages directed toward the device, specifically those targeting the cs_broker component.

Compensating Controls: Implement strict network segmentation and ensure the router management interface is not accessible from the public internet to mitigate the risk of remote exploitation.

Exploitation status

Public Exploit Available: No (no confirmed public exploit exists in the available data).

Analyst recommendation

This vulnerability represents a severe risk to the availability of TOTOLINK T6 devices. Administrators must prioritize restricting external access to the device management and messaging services immediately. Apply any forthcoming firmware patches from the vendor as soon as they become available to permanently remediate this access control failure.

More TOTOLINK CVEs

Sources