CVE-2026-51768
TOTOLINK · T6
An improper access control flaw in TOTOLINK T6 allows unauthenticated attackers to modify privileged Quality of Service (QoS) policies via crafted MQTT messages.
Executive summary
An unauthenticated access control vulnerability in the TOTOLINK T6 router enables remote attackers to manipulate critical network traffic policies, posing a high risk to network integrity.
Vulnerability
This vulnerability resides within the setElinkQosConfig function, which fails to perform necessary authentication checks. An attacker can transmit a crafted MQTT message to the cs_broker component to modify privileged QoS configurations without requiring valid credentials.
Business impact
Successful exploitation allows unauthorized modification of QoS policies, which can lead to traffic manipulation, service degradation, or potential denial of service for critical network segments. With a CVSS score of 7.5, this vulnerability represents a significant risk to operational continuity, as attackers could prioritize or throttle traffic to disrupt legitimate business functions.
Remediation
Immediate Action: Review the official TOTOLINK advisory and website for available firmware updates addressing this flaw and apply them to all affected T6 devices immediately.
Proactive Monitoring: Monitor the cs_broker component logs and network traffic for anomalous MQTT message patterns or unauthorized configuration change requests.
Compensating Controls: Restrict network access to the MQTT management interface by implementing firewall rules that limit communication to authorized internal management workstations only.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The high severity of this vulnerability necessitates immediate attention to prevent unauthorized network control. Administrators should isolate affected TOTOLINK T6 devices from public-facing networks until a verified vendor patch is applied and confirmed to remediate the access control deficiency.