CVE-2026-51767

9.8

TOTOLINK · T6

TOTOLINK T6 routers contain an incorrect access control vulnerability in the recvClearPairCfg function, allowing unauthenticated attackers to trigger device reboots via crafted MQTT messages.

Executive summary

A critical vulnerability in TOTOLINK T6 routers allows unauthenticated remote attackers to reset pairing states and force device reboots, potentially leading to a total loss of service.

Vulnerability

The flaw exists within the recvClearPairCfg function of the cs_broker component. Unauthenticated attackers can send a crafted MQTT message to the device to execute unauthorized configuration resets and system reboots.

Business impact

The CVSS score of 9.8 reflects the extreme severity of this vulnerability, as it allows for trivial remote exploitation without any user interaction or authentication. A successful exploit results in a denial of service for the affected network, potentially disrupting business operations, damaging internal communication, and requiring manual recovery of the hardware.

Remediation

Immediate Action: Consult the official TOTOLINK support portal to determine if a firmware update is available for the T6 model and apply it immediately.

Proactive Monitoring: Monitor network traffic for unusual MQTT protocol activity targeting internal IoT or networking hardware, especially from unauthorized external sources.

Compensating Controls: Restrict access to the MQTT broker interface at the network perimeter by implementing firewall rules that block unsolicited inbound traffic to the ports used by the cs_broker component.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical CVSS severity and the ease of exploitation, organizations using TOTOLINK T6 devices must prioritize securing the device management interface. Administrators should immediately isolate these devices from public-facing network segments and apply any vendor-supplied patches as soon as they are released to prevent potential service disruption.

More TOTOLINK CVEs all →

Sources