CVE-2026-51750
TOTOLINK · T6
An incorrect access control vulnerability in the TOTOLINK T6 updatePriChannel function allows unauthenticated attackers to manipulate mesh channel settings via crafted MQTT messages.
Executive summary
A critical access control vulnerability in TOTOLINK T6 routers allows unauthenticated remote attackers to hijack mesh network configurations.
Vulnerability
The flaw resides within the updatePriChannel function, which lacks proper authentication checks. An unauthenticated attacker can send a crafted MQTT message to the cs_broker component to rescan and switch the primary mesh channel, leading to potential network disruption or interception.
Business impact
The CVSS score of 9.8 reflects the high severity of this vulnerability, as it allows full control over network mesh topology without any prior authentication. Successful exploitation can lead to significant service denial, unauthorized network reconfiguration, and potential traffic interception, posing a severe risk to organizational connectivity and data confidentiality.
Remediation
Immediate Action: Review the official TOTOLINK support portal for firmware updates addressing this flaw; if no patch is available for your specific build, restrict access to the MQTT broker interface.
Proactive Monitoring: Monitor network traffic for anomalous MQTT messages directed at the cs_broker component or unexpected changes in mesh network configuration.
Compensating Controls: Implement network segmentation to isolate the management interface of the router from public-facing or untrusted network segments to prevent remote exploitation.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the critical CVSS severity and the potential for full network control, administrators should treat this vulnerability with the highest urgency. If a firmware update is not currently available, it is imperative to implement strict network-level access controls to ensure the device is not reachable by unauthorized parties.