CVE-2026-51763

TOTOLINK · T6

An access control vulnerability in TOTOLINK T6 allows unauthenticated remote attackers to disconnect wireless clients by sending a crafted MQTT message to the cs_broker component.

Executive summary

A critical access control flaw in TOTOLINK T6 routers allows unauthenticated attackers to remotely disrupt wireless connectivity, necessitating immediate network-level isolation.

Vulnerability

The vulnerability exists due to incorrect access control within the freeStaClient function. An unauthenticated attacker can exploit this by sending a malformed MQTT message to the cs_broker component to force the disconnection of wireless clients.

Business impact

This vulnerability carries a CVSS score of 9.8, indicating a critical severity level due to the ease of exploitation and the potential for a complete denial of service for wireless users. Successful exploitation results in significant operational disruption, as attackers can repeatedly drop legitimate wireless connections, leading to productivity loss and potential security concerns regarding the availability of network infrastructure.

Remediation

Immediate Action: Review the official TOTOLINK support portal for firmware updates addressing this flaw and apply them to all T6 units immediately. If no patch is currently available, restrict access to the MQTT broker port from untrusted networks.

Proactive Monitoring: Monitor network traffic for unusual MQTT protocol activity, particularly messages directed at the cs_broker component originating from external or unauthorized internal IP addresses.

Compensating Controls: Implement firewall rules or Access Control Lists (ACLs) to block external access to the specific ports utilized by the MQTT broker, effectively isolating the management interface from the public internet.

Exploitation status

Public Exploit Available: No (the referenced GitHub repositories are vendor coordination trackers and do not contain functional exploit code).

Analyst recommendation

Given the critical nature of this vulnerability and the potential for widespread wireless service denial, organizations using the affected TOTOLINK T6 hardware must prioritize mitigation. Administrators should proactively restrict network access to the device management interfaces and remain vigilant for firmware release notifications from the vendor to resolve the underlying access control logic flaw.

More TOTOLINK CVEs

Sources