CVE-2026-51760
TOTOLINK · T6
An access control flaw in the TOTOLINK T6 firmware allows unauthenticated attackers to trigger mass firmware updates on mesh slave devices via crafted MQTT messages.
Executive summary
A critical vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to force unauthorized firmware updates across mesh networks, potentially leading to full system compromise.
Vulnerability
This vulnerability involves incorrect access control within the informSyncUpgfw function, which permits an unauthenticated attacker to inject crafted MQTT messages into the cs_broker component. This action forces downstream mesh slave devices to initiate unauthorized firmware update processes.
Business impact
The exploitation of this flaw carries a CVSS score of 9.8, indicating a critical severity level due to the ease of remote, unauthenticated access. Successful exploitation could result in total loss of device integrity, widespread network disruption, and potential persistent unauthorized access if attackers force the installation of malicious or compromised firmware.
Remediation
Immediate Action: Contact TOTOLINK support or monitor the official vendor download portal for a firmware update that addresses the informSyncUpgfw function vulnerability.
Proactive Monitoring: Monitor network traffic for anomalous MQTT messaging patterns directed at the cs_broker component and inspect device logs for unauthorized firmware update initiation signals.
Compensating Controls: Isolate mesh management interfaces from the public internet using firewalls or VLANs to prevent unauthenticated access to the MQTT broker.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the critical nature of this flaw and the potential for large scale disruption to mesh network environments, administrators should treat this as a high priority item. If a vendor patch is not immediately available, restrict network access to the management components of the TOTOLINK T6 to prevent exploitation by external actors.