ZeroHour

CVE-2026-51767

large

Unauthenticated MQTT access-control flaw in TOTOLINK T6 enables forced reboot

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51767 is an improper access control issue (CWE-284) in the recvClearPairCfg function of TOTOLINK T6 mesh Wi-Fi firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted MQTT message to the device's cs_broker component, which the firmware processes without any access control check. Successful abuse resets the device's pairing state and forces a reboot, disrupting mesh connectivity and device availability until the unit is re-paired and comes back online. Owners and operators running the named TOTOLINK T6 firmware are affected, and the flaw is network-reachable with no privileges or user interaction required, earning a critical CVSS 3.1 score of 9.8. No public proof-of-concept or in-the-wild exploitation is currently known, the issue is not in CISA's KEV catalog, and EPSS puts the 30-day exploitation probability at only about 0.4%.

What to do: Check TOTOLINK T6 units for firmware 4.1.5cu.748_B20211015 and upgrade when TOTOLINK publishes a fix (no patched version is named in the available data). In the interim, restrict the device's MQTT/cs_broker interface to the trusted LAN, avoid exposing device management services to the internet, and re-pair the mesh if you observe unexpected reboots or cleared pairing state.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (only this version is named in the advisory; other versions are not specified)
Estimated exposure
largeplausibly on the order of tens of thousands of consumer devices installed, though only a subset with externally reachable MQTT interfaces may actually be… — No published install-base or internet-scan counts exist for the T6 specifically, so this heuristic estimate rests on TOTOLINK's standing as a budget consumer Wi-Fi vendor with broad single-model retail deployments and the common pattern of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pairing state and reboot the device via sending a crafted MQTT message to the cs_broker component.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.