CVE-2026-51766
nicheBroken access control allows unauthenticated reboot of TOTOLINK T6 routers
TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015 contain an incorrect access control flaw (CWE-284) in the setDevReboot function of the cs_broker component. An unauthenticated attacker can send a crafted MQTT message to the broker to invoke setDevReboot without any authentication, rebooting the targeted device; when the targeted unit is acting as a mesh master, the reboot command fans out to the mesh slave nodes as well. The flaw has no confidentiality or integrity impact, but it gives an attacker a denial-of-service primitive, since repeated crafted messages can keep a single router, or an entire mesh network, continuously rebooting and offline. Any TOTOLINK T6 running the affected firmware is exposed, with internet-facing units or devices reachable by untrusted LAN or Wi-Fi clients at greatest risk. The issue is not in CISA KEV, no public proof-of-concept is known, and EPSS currently estimates only a 0.4% chance of exploitation within the next 30 days.
What to do: T6 owners should check whether they run firmware 4.1.5cu.748_B20211015 and install any newer firmware TOTOLINK releases addressing this issue (no fixed version is documented yet). Until then, avoid exposing the device's MQTT broker interface to the internet or untrusted networks and restrict management access to trusted LAN clients, since the reboot command is delivered via unauthenticated MQTT. Operators of T6 mesh deployments should treat unexplained simultaneous reboots of a master and its slave nodes as a possible indicator of exploitation.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (confirmed affected; broader affected ranges not specified in available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mesh slaves via sending a crafted MQTT message to the cs_broker component.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.