ZeroHour

CVE-2026-51764

moderate

Unauthenticated MQTT file overwrite in TOTOLINK T6 router firmware

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an improper access control flaw (CWE-284) in the recvSlaveCloudCheckStatus function, which handles cloud connectivity check status. An unauthenticated remote attacker can send a crafted MQTT message to the cs_broker component and overwrite the files used to track cloud check results, with no credentials or user interaction required. The practical impact is tampering with or corrupting the router's cloud-status tracking data, which can disrupt or falsify cloud connectivity reporting; the CVSS 9.8 critical score reflects high confidentiality, integrity, and availability impact on the affected system. Owners of TOTOLINK T6 routers running the affected firmware are exposed, particularly where the MQTT/cs_broker interface is reachable from untrusted networks. There is currently no evidence of exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.4% chance of exploitation in the next 30 days.

What to do: Check the router's firmware version and upgrade to a patched TOTOLINK release when the vendor publishes one (no fixed version is specified in the available data). As an interim mitigation, restrict access to the device's MQTT/cs_broker interface so it is not reachable from untrusted or internet-facing networks, and monitor cloud-status behavior for signs of tampering.

Affected
TOTOLINK T6 router (firmware)4.1.5cu.748_B20211015 (the specific build cited in the advisory; whether other firmware versions are affected is not stated in the data)
Estimated exposure
moderatelikely on the order of thousands of internet-exposed TOTOLINK T6 devices (exact count unknown) — Internet-wide scans regularly surface tens of thousands of exposed TOTOLINK routers across the vendor's consumer lineup, and the T6 is one model among many, so a low-thousands share is a plausible order of magnitude; no vendor install-base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking files via sending a crafted MQTT message to the cs_broker component.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.