ZeroHour

CVE-2026-51750

niche

Unauthenticated access-control flaw in TOTOLINK T6 mesh router MQTT handler

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

TOTOLINK T6 mesh router firmware 4.1.5cu.748_B20211015 contains an incorrect access control flaw (CWE-284) in the updatePriChannel function of the cs_broker component. An unauthenticated attacker who can reach the device's MQTT interface can send a crafted MQTT message that forces the router to rescan and switch its primary mesh channel, allowing them to disrupt or reconfigure the mesh wireless backhaul without any credentials. The CVSS 3.1 score of 9.8 (critical) reflects network-based exploitation requiring no privileges or user interaction. Only TOTOLINK T6 devices running the named firmware build are confirmed affected; owners of other TOTOLINK models or firmware versions should verify their exposure with the vendor. No public proof-of-concept, KEV listing, or in-the-wild exploitation is known, and EPSS estimates only about a 0.4% probability of exploitation in the next 30 days.

What to do: TOTOLINK T6 owners should check their current firmware version and, if running 4.1.5cu.748_B20211015, monitor TOTOLINK's download/support page for a corrected release (no fixed version is named in the available data). Until patched, restrict access to the router's MQTT/cs_broker interface to trusted clients and avoid exposing management services to the internet or untrusted networks. Defenders should watch for a vendor advisory, since no public PoC or patch details are yet available.

Affected
TOTOLINK T6 mesh router4.1.5cu.748_B20211015
Estimated exposure
nichelikely on the order of thousands to tens of thousands of devices worldwide (no authoritative install base available) — No public install-base data exists for the T6; TOTOLINK is a budget consumer router vendor, this is a single mesh model with only one named affected firmware build, and exploitation additionally requires reachability of the device's…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channel via sending a crafted MQTT message to the cs_broker component.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.