CVE-2026-51751
TOTOLINK · T6
An unauthenticated access control vulnerability in the TOTOLINK T6 mesh management component allows remote attackers to delete slave devices and reboot the system via crafted MQTT messages.
Executive summary
A critical vulnerability in the TOTOLINK T6 mesh management system allows unauthenticated attackers to perform unauthorized device removal and system reboots, posing a severe risk to network availability.
Vulnerability
The vulnerability resides in the delSlaveDevice function, which lacks proper access control checks. Unauthenticated attackers can exploit this flaw by sending a crafted MQTT message to the cs_broker component to trigger unauthorized administrative actions.
Business impact
The ability for an unauthenticated remote attacker to force a system reboot and manipulate mesh topology represents a significant threat to operational continuity. Given the CVSS score of 9.8, this vulnerability allows for complete impact on availability and system integrity, potentially leading to widespread network outages and service disruption.
Remediation
Immediate Action: Review the official TOTOLINK support portal for firmware updates addressing this vulnerability and apply them as soon as they become available.
Proactive Monitoring: Monitor network traffic for unusual MQTT messages directed at the cs_broker component, specifically those targeting mesh management functions.
Compensating Controls: If a patch is unavailable, isolate the management interface from the public internet using firewall rules to restrict MQTT traffic to trusted internal sources only.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability presents a critical risk to TOTOLINK T6 devices due to the lack of authentication required to execute disruptive commands. Organizations should prioritize isolating affected hardware from external network exposure until a vendor-supplied firmware update is verified and deployed to remediate the underlying access control failure.