CVE-2026-51767
largeUnauthenticated MQTT access-control flaw in TOTOLINK T6 enables forced reboot
CVE-2026-51767 is an improper access control issue (CWE-284) in the recvClearPairCfg function of TOTOLINK T6 mesh Wi-Fi firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can send a crafted MQTT message to the device's cs_broker component, which the firmware processes without any access control check. Successful abuse resets the device's pairing state and forces a reboot, disrupting mesh connectivity and device availability until the unit is re-paired and comes back online. Owners and operators running the named TOTOLINK T6 firmware are affected, and the flaw is network-reachable with no privileges or user interaction required, earning a critical CVSS 3.1 score of 9.8. No public proof-of-concept or in-the-wild exploitation is currently known, the issue is not in CISA's KEV catalog, and EPSS puts the 30-day exploitation probability at only about 0.4%.
What to do: Check TOTOLINK T6 units for firmware 4.1.5cu.748_B20211015 and upgrade when TOTOLINK publishes a fix (no patched version is named in the available data). In the interim, restrict the device's MQTT/cs_broker interface to the trusted LAN, avoid exposing device management services to the internet, and re-pair the mesh if you observe unexpected reboots or cleared pairing state.
| TOTOLINK T6 | 4.1.5cu.748_B20211015 (only this version is named in the advisory; other versions are not specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pairing state and reboot the device via sending a crafted MQTT message to the cs_broker component.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.