ZeroHour

CVE-2026-51743

Access control flaw in TOTOLINK T6 lets attackers disable guest Wi-Fi via MQTT

CVSS 3.1
9.1 critical
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-51743 is an incorrect access control flaw (CWE-284) in the guest_wifi_sync function of the TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted MQTT message to the device's cs_broker component, bypassing the access controls that should restrict this function. A successful attack allows the attacker to disable guest virtual AP interfaces, disrupting guest Wi-Fi service on affected routers (the assigned CVSS 3.1 score of 9.1 rates it critical, with network attack vector, no privileges or user interaction required, and high confidentiality and integrity impacts). Users running the affected TOTOLINK T6 firmware are at risk, particularly devices whose MQTT/cs_broker interface is reachable from untrusted networks. There is currently no known exploitation, no public proof-of-concept, and the vulnerability is not listed in CISA's KEV, with a modest EPSS probability of 0.4% over the next 30 days.

What to do: Check whether any TOTOLINK T6 devices on your networks run firmware 4.1.5cu.748_B20211015 and monitor TOTOLINK for a corrected firmware release, as no fixed version is specified in the available data. In the meantime, restrict unauthenticated access to the MQTT broker (cs_broker) port on these devices, e.g. by firewalling the WAN side or limiting MQTT access to trusted management networks. If guest Wi-Fi is not needed, consider disabling the guest virtual AP feature to reduce impact.

Affected
TOTOLINK T64.1.5cu.748_B20211015
Estimated exposure
unknown (single consumer/SOHO router model; plausibly thousands to tens of thousands of devices) — No install-base or internet-exposure scan data specific to the TOTOLINK T6 model is provided in the available data; TOTOLINK T6 is a consumer/SOHO router, so affected deployments are plausibly in the thousands but cannot be confirmed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via sending a crafted MQTT message to the cs_broker component.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.