CVE-2026-51765

9.8

TOTOLINK · T6

An incorrect access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to manipulate mesh neighbor records by sending crafted MQTT messages to the cs_broker component.

Executive summary

A critical access control vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to manipulate network mesh configurations, posing a significant risk of traffic interception.

Vulnerability

The vulnerability resides in the recvIndirectMeshInfo function, which fails to perform proper authorization checks. Unauthenticated attackers can exploit this by sending a malformed MQTT message to the cs_broker service, enabling the insertion or replacement of mesh neighbor records.

Business impact

Successful exploitation allows an attacker to compromise the integrity of the network mesh topology. This could lead to unauthorized traffic interception, redirection, or denial of service for connected devices. Given the CVSS score of 9.8, this vulnerability is classified as critical, as it requires no user interaction and no authentication to execute, potentially facilitating widespread network compromise.

Remediation

Immediate Action: Review the official TOTOLINK support portal for firmware updates addressing this flaw and apply the latest available version immediately.

Proactive Monitoring: Monitor network traffic for unusual MQTT messages or unexpected modifications to mesh neighbor tables within the router settings.

Compensating Controls: Restrict access to the MQTT broker and management interfaces by placing the device behind a firewall, ensuring it is not directly exposed to the public internet.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit or weaponized module available at this time.

Analyst recommendation

This vulnerability presents a severe risk to network infrastructure security. Administrators should prioritize identifying any TOTOLINK T6 devices currently in production and verify their firmware status against the vendor recommendations. If a patch is available, it must be deployed immediately to prevent potential network manipulation by external actors.

More TOTOLINK CVEs all →

History

CVE Brief tracked this CVE 5 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.8 (3.1)
  4. Analyst report written
  5. Published in the daily brief critical section, early-warning entry

Sources