CVE-2026-51754

9.8

TOTOLINK · T6

An access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to overwrite the slave IP inventory via crafted MQTT messages sent to the cs_broker component.

Executive summary

A critical access control vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to manipulate network inventory, creating significant potential for unauthorized system control.

Vulnerability

The flaw resides in the updateSlaveIpList function, which fails to perform necessary authentication checks before processing MQTT messages. An unauthenticated attacker can exploit this weakness by sending a crafted MQTT message directly to the cs_broker component, resulting in the unauthorized modification of the slave IP inventory state.

Business impact

The exploitation of this vulnerability carries a CVSS score of 9.8, reflecting its critical nature and ease of remote execution. Successful compromise allows an attacker to manipulate core networking configurations, which could lead to full device takeover, traffic interception, or the permanent disruption of network services for all connected users.

Remediation

Immediate Action: Review the official TOTOLINK support portal for firmware updates addressing this vulnerability and apply them immediately. In the absence of a specific patch, ensure the device is not directly exposed to the public internet.

Proactive Monitoring: Monitor network traffic for unusual MQTT protocol activity targeting the device, particularly messages directed toward the cs_broker component.

Compensating Controls: Implement strict network segmentation and restrict access to the device management interface to trusted internal IP addresses only. Use a firewall to block unsolicited MQTT traffic originating from outside the local network.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical severity of this vulnerability and the lack of authentication required to execute the attack, immediate action is required. Organizations utilizing the TOTOLINK T6 must restrict network access to the device and prioritize the application of any vendor-supplied firmware updates to mitigate the risk of remote exploitation.

More TOTOLINK CVEs all →

History

CVE Brief tracked this CVE 5 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.8 (3.1)
  4. Analyst report written
  5. Published in the daily brief critical section, early-warning entry

Sources