CVE-2026-51764
TOTOLINK · T6
An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to overwrite cloud-result tracking files via crafted MQTT messages.
Executive summary
A critical vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to perform unauthorized file overwrites, potentially leading to a complete compromise of the device.
Vulnerability
The flaw exists within the recvSlaveCloudCheckStatus function, which fails to properly validate access control for incoming traffic. An unauthenticated attacker can exploit this by sending a specifically crafted MQTT message to the cs_broker component, resulting in the ability to overwrite sensitive cloud-result tracking files.
Business impact
The exploitation of this vulnerability carries a CVSS score of 9.8, reflecting its critical nature and ease of access for remote attackers. Successful exploitation could lead to total loss of device integrity, unauthorized configuration changes, or the potential for further lateral movement within the local network, posing significant risks to operational security and data privacy.
Remediation
Immediate Action: Consult the official TOTOLINK support portal at the provided reference link to determine if a firmware update is available for your specific hardware revision. If no patch is currently available, disconnect the device from public-facing internet access immediately.
Proactive Monitoring: Monitor network traffic for unusual MQTT protocol activity or unexpected communication directed toward the cs_broker component. Review system logs for signs of unauthorized file modification or unexpected service restarts.
Compensating Controls: Implement strict network segmentation to isolate the affected TOTOLINK T6 device from sensitive internal segments. Ensure that the device is not accessible from the wide area network and restrict management access to trusted local IP addresses only.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability presents a severe risk due to the lack of authentication required to execute the attack. Organizations currently utilizing the TOTOLINK T6 router should prioritize isolating these devices from external networks until a vendor-supplied firmware update is verified and applied. Continuous monitoring of network boundaries is essential to prevent unauthorized access to the affected components.