CVE-2026-51744

TOTOLINK · T6

An incorrect access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to force unauthorized mesh configuration synchronization via crafted MQTT messages.

Executive summary

A critical vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to manipulate mesh network configurations, potentially leading to a full system compromise.

Vulnerability

This vulnerability resides in the recv_mesh_info_sync function, where improper access control permits an unauthenticated attacker to inject malicious mesh configuration data via the cs_broker MQTT component.

Business impact

The exploitation of this flaw carries a CVSS score of 9.8, indicating a critical risk of complete system takeover. Successful execution allows an attacker to control network traffic flow, intercept sensitive data, or render the device unusable, leading to significant service disruption and potential loss of data confidentiality and integrity.

Remediation

Immediate Action: Contact TOTOLINK support or monitor the official vendor download portal for a firmware update that addresses the MQTT message validation flaw.

Proactive Monitoring: Inspect network traffic for unusual MQTT activity directed at the cs_broker component and review system logs for unauthorized configuration changes.

Compensating Controls: Isolate affected TOTOLINK T6 devices from public-facing networks and implement firewall rules to restrict access to MQTT ports from untrusted sources.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the referenced security research repositories.

Analyst recommendation

Given the critical CVSS severity and the existence of public proof-of-concept material, this vulnerability poses an immediate risk to network infrastructure. Administrators should prioritize the isolation of vulnerable TOTOLINK T6 units until a vendor-supplied security update can be verified and applied to the affected firmware.

More TOTOLINK CVEs

Sources