ZeroHour

CVE-2026-51611

moderate

Unauthenticated forced-reboot flaw in TOTOLINK T6 via crafted MQTT message

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51611 is an improper access-control flaw (CWE-284) in the startSlaveReboot function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker who can reach the device's MQTT service can send a crafted MQTT message that forces an arbitrary reboot, producing a denial-of-service condition on the router; the flaw is rated 9.8 Critical under CVSS 3.1. Any TOTOLINK T6 running the affected firmware is exposed, most practically units whose MQTT port is reachable from the WAN (e.g., via cloud/app management) or where an attacker already has LAN access. There are no known exploitation reports, no public proof-of-concept, and the vulnerability is not in CISA's KEV catalog, with EPSS estimating only a 0.4% probability of exploitation in the next 30 days.

What to do: Check T6 routers for firmware 4.1.5cu.748_B20211015 and apply patched firmware from TOTOLINK when available (no fixed version is specified in the current data). Until then, do not expose the device's MQTT port to the WAN, restrict MQTT access with firewall rules, and disable cloud/app-based remote management if it is not needed. Treat unexplained reboots of affected units as potential indicators of probing or exploitation.

Affected
TOTOLINK T64.1.5cu.748_B20211015
Estimated exposure
moderateon the order of 10,000-100,000 directly exposed units (public scans show tens of thousands of internet-exposed TOTOLINK routers; T6-specific counts are… — Public internet scans (e.g., Shodan/FOFA) typically index tens of thousands of exposed TOTOLINK consumer routers, and the T6 is one of the vendor's widely distributed models, so tens of thousands of units, of which a subset have MQTT…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a crafted MQTT message.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.