ZeroHour

CVE-2026-51765

Unauthenticated MQTT record injection in TOTOLINK T6 mesh firmware

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51765 is an incorrect access control flaw (CWE-284) in the recvIndirectMeshInfo function of the cs_broker component on the TOTOLINK T6 mesh router, firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted MQTT message to the cs_broker listener and insert or replace mesh neighbor records without any credentials. Depending on network placement of the MQTT service, this could let an attacker manipulate the device's view of its mesh topology, and the critical CVSS 9.8 score reflects potential for high-impact changes to confidentiality, integrity, and availability. Users running the named TOTOLINK T6 firmware are affected; the data documents this specific version and does not enumerate other firmware revisions. Exploitation has not been reported: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.4% probability of exploitation in the next 30 days.

What to do: Check any deployed TOTOLINK T6 units for firmware 4.1.5cu.748_B20211015 and monitor TOTOLINK's site for a patched firmware release before upgrading, since no fixed version is named in the available data. As an interim mitigation, restrict the device's MQTT/cs_broker listener so it is not reachable from the WAN (and limit it to trusted mesh nodes where possible). Keep the device off direct internet exposure until vendor guidance is available.

Affected
TOTOLINK T6 mesh router4.1.5cu.748_B20211015 (version cited in the advisory; other firmware revisions may be affected but are not documented in the available data)
Estimated exposure
unknown; plausibly in the thousands of devices at most — No public install-base or internet-scan counts exist for the T6 specifically, but TOTOLINK's consumer router line routinely appears in internet-wide scans in the tens of thousands of exposed units, so this single older mesh model is likely…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted MQTT message to the cs_broker component.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.