CVE-2026-51769

9.8

TOTOLINK · T6

An access control flaw in the TOTOLINK T6 remoteCloudUpdateCheck function allows unauthenticated attackers to trigger unauthorized cloud update workflows via crafted MQTT messages.

Executive summary

A critical access control vulnerability in TOTOLINK T6 routers allows unauthenticated remote attackers to manipulate update workflows, posing a severe risk of unauthorized system control.

Vulnerability

The vulnerability exists within the remoteCloudUpdateCheck function, which fails to perform proper authentication checks. An unauthenticated attacker can send a crafted MQTT message to the cs_broker component to restart the cloud update process, potentially leading to full system compromise.

Business impact

The CVSS score of 9.8 reflects the extreme risk posed by this vulnerability, as it allows for unauthenticated remote execution. Successful exploitation could lead to unauthorized firmware updates or system reboots, resulting in significant operational downtime, potential data interception, and total loss of device integrity.

Remediation

Immediate Action: Review the official TOTOLINK support portal for firmware updates that address this issue, as no specific patch version is currently identified. If no patch is available, restrict network access to the device management interface and MQTT broker port to trusted management subnets only.

Proactive Monitoring: Monitor network traffic for anomalous MQTT traffic directed at the cs_broker component. Review system logs for unexpected update workflow initiation or unauthorized administrative commands.

Compensating Controls: Implement strict network segmentation to isolate the device from the public internet. Use a firewall or Access Control List (ACL) to block external access to the MQTT broker port.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical CVSS severity and the nature of the flaw, organizations utilizing TOTOLINK T6 devices must prioritize the hardening of network perimeters. Administrators should immediately restrict access to the affected service and maintain vigilance for vendor security bulletins. Applying vendor-supplied firmware updates remains the only definitive method to eliminate this risk.

More TOTOLINK CVEs all →

History

CVE Brief tracked this CVE 5 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.8 (3.1)
  4. Analyst report written
  5. Published in the daily brief critical section, early-warning entry

Sources