CVE-2026-51762
9.8TOTOLINK · T6
An access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to manipulate mesh metadata and state via crafted MQTT messages, potentially leading to full system compromise.
Executive summary
A critical access control flaw in TOTOLINK T6 routers allows unauthenticated remote attackers to disrupt mesh networking and potentially achieve full system impact.
Vulnerability
This vulnerability involves incorrect access control within the meshInfoKick function, which fails to validate the identity of the requester. An unauthenticated attacker can send a crafted MQTT message to the cs_broker component to clear mesh state data and force metadata regeneration.
Business impact
The CVSS score of 9.8 reflects the high potential for total system compromise, including loss of confidentiality, integrity, and availability. Successful exploitation allows an attacker to disrupt network operations or manipulate mesh configurations, which could lead to unauthorized network access or complete denial of service for connected devices.
Remediation
Immediate Action: Review the official TOTOLINK support portal for firmware updates addressing this vulnerability and apply them immediately upon release.
Proactive Monitoring: Monitor network traffic for unusual MQTT messages directed at internal router components and inspect system logs for unexpected mesh metadata regeneration events.
Compensating Controls: Implement network segmentation to isolate the management interface of the router from public-facing segments and consider restricting MQTT traffic to authorized devices only.
Exploitation status
Public Exploit Available: No (The provided references are researcher coordination documents and do not constitute a functional public exploit).
Analyst recommendation
Given the critical CVSS severity and the lack of authentication required for exploitation, this vulnerability poses a significant risk to network integrity. Security teams should prioritize monitoring the TOTOLINK vendor advisory page and apply the necessary firmware update as soon as the manufacturer releases a fix.
More TOTOLINK CVEs all →
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.8 (3.1)
- Analyst report written
- Published in the daily brief critical section, early-warning entry