CVE-2026-51611
moderateUnauthenticated forced-reboot flaw in TOTOLINK T6 via crafted MQTT message
CVE-2026-51611 is an improper access-control flaw (CWE-284) in the startSlaveReboot function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker who can reach the device's MQTT service can send a crafted MQTT message that forces an arbitrary reboot, producing a denial-of-service condition on the router; the flaw is rated 9.8 Critical under CVSS 3.1. Any TOTOLINK T6 running the affected firmware is exposed, most practically units whose MQTT port is reachable from the WAN (e.g., via cloud/app management) or where an attacker already has LAN access. There are no known exploitation reports, no public proof-of-concept, and the vulnerability is not in CISA's KEV catalog, with EPSS estimating only a 0.4% probability of exploitation in the next 30 days.
What to do: Check T6 routers for firmware 4.1.5cu.748_B20211015 and apply patched firmware from TOTOLINK when available (no fixed version is specified in the current data). Until then, do not expose the device's MQTT port to the WAN, restrict MQTT access with firewall rules, and disable cloud/app-based remote management if it is not needed. Treat unexplained reboots of affected units as potential indicators of probing or exploitation.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a crafted MQTT message.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.