ZeroHour

CVE-2026-51766

niche

Broken access control allows unauthenticated reboot of TOTOLINK T6 routers

CVSS 3.1
7.5 high
EPSS
<1%p36
Published
()
Modified
AI analysis

TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015 contain an incorrect access control flaw (CWE-284) in the setDevReboot function of the cs_broker component. An unauthenticated attacker can send a crafted MQTT message to the broker to invoke setDevReboot without any authentication, rebooting the targeted device; when the targeted unit is acting as a mesh master, the reboot command fans out to the mesh slave nodes as well. The flaw has no confidentiality or integrity impact, but it gives an attacker a denial-of-service primitive, since repeated crafted messages can keep a single router, or an entire mesh network, continuously rebooting and offline. Any TOTOLINK T6 running the affected firmware is exposed, with internet-facing units or devices reachable by untrusted LAN or Wi-Fi clients at greatest risk. The issue is not in CISA KEV, no public proof-of-concept is known, and EPSS currently estimates only a 0.4% chance of exploitation within the next 30 days.

What to do: T6 owners should check whether they run firmware 4.1.5cu.748_B20211015 and install any newer firmware TOTOLINK releases addressing this issue (no fixed version is documented yet). Until then, avoid exposing the device's MQTT broker interface to the internet or untrusted networks and restrict management access to trusted LAN clients, since the reboot command is delivered via unauthenticated MQTT. Operators of T6 mesh deployments should treat unexplained simultaneous reboots of a master and its slave nodes as a possible indicator of exploitation.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (confirmed affected; broader affected ranges not specified in available data)
Estimated exposure
nichelikely on the order of thousands of devices worldwide; no public install counts exist for this specific model — No active-install or scan data is published for the T6 specifically; TOTOLINK devices across all models appear in public internet-exposure scans only in the tens of thousands, and this single 2021-era consumer mesh model is plausibly a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mesh slaves via sending a crafted MQTT message to the cs_broker component.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.