CVE-2026-51770

TOTOLINK · T6

TOTOLINK T6 allows unauthenticated attackers to manipulate QoS settings via crafted MQTT messages sent to the cs_broker component.

Executive summary

A critical vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to achieve full control over device QoS configurations via malicious MQTT messages.

Vulnerability

This is an incorrect access control vulnerability located in the sendToMasterQosConfig function. It permits an unauthenticated attacker to inject arbitrary QoS settings by interacting with the cs_broker component.

Business impact

The CVSS score of 9.8 reflects the high potential for system compromise. An attacker who successfully exploits this flaw can manipulate network traffic prioritization, potentially leading to service degradation, denial of service, or the redirection of traffic flows. Such an impact compromises the integrity and availability of the network infrastructure managed by the affected device.

Remediation

Immediate Action: Consult the official TOTOLINK support portal for firmware updates or security patches for the T6 model. If no patch is available, isolate the management interface of the device from untrusted networks immediately.

Proactive Monitoring: Monitor network traffic for suspicious MQTT protocol activity or unexpected changes in Quality of Service configurations. Review device logs for unauthorized access attempts or unusual configuration modifications.

Compensating Controls: Implement strict network segmentation to ensure the device management interface is not exposed to the public internet. Use a firewall to restrict access to the MQTT broker port to trusted internal IP addresses only.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical severity and the potential for remote exploitation without authentication, administrators must prioritize the security of their TOTOLINK T6 deployments. If firmware updates are not currently provided by the vendor, network-level isolation is the only effective defense against this vulnerability. Failure to secure the device could allow attackers to manipulate critical network traffic controls.

More TOTOLINK CVEs

Sources