CVE-2026-51768

TOTOLINK · T6

An improper access control flaw in TOTOLINK T6 allows unauthenticated attackers to modify privileged Quality of Service (QoS) policies via crafted MQTT messages.

Executive summary

An unauthenticated access control vulnerability in the TOTOLINK T6 router enables remote attackers to manipulate critical network traffic policies, posing a high risk to network integrity.

Vulnerability

This vulnerability resides within the setElinkQosConfig function, which fails to perform necessary authentication checks. An attacker can transmit a crafted MQTT message to the cs_broker component to modify privileged QoS configurations without requiring valid credentials.

Business impact

Successful exploitation allows unauthorized modification of QoS policies, which can lead to traffic manipulation, service degradation, or potential denial of service for critical network segments. With a CVSS score of 7.5, this vulnerability represents a significant risk to operational continuity, as attackers could prioritize or throttle traffic to disrupt legitimate business functions.

Remediation

Immediate Action: Review the official TOTOLINK advisory and website for available firmware updates addressing this flaw and apply them to all affected T6 devices immediately.

Proactive Monitoring: Monitor the cs_broker component logs and network traffic for anomalous MQTT message patterns or unauthorized configuration change requests.

Compensating Controls: Restrict network access to the MQTT management interface by implementing firewall rules that limit communication to authorized internal management workstations only.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The high severity of this vulnerability necessitates immediate attention to prevent unauthorized network control. Administrators should isolate affected TOTOLINK T6 devices from public-facing networks until a verified vendor patch is applied and confirmed to remediate the access control deficiency.

More TOTOLINK CVEs

Sources