ZeroHour

CVE-2026-51769

moderate

Unauthenticated access control flaw in TOTOLINK T6 MQTT cloud update check

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51769 is an incorrect access control issue (CWE-284) in the remoteCloudUpdateCheck function of the cs_broker component in TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted MQTT message directly to the cs_broker component, requiring no credentials or user interaction. The documented impact is the ability to restart the device's cloud update check workflow, which can force unexpected cloud-update activity; the assigned CVSS 3.1 base score is 9.8 (critical), indicating high confidentiality, integrity, and availability impact. Any TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015 is affected, particularly units whose MQTT/cs_broker interface is reachable from untrusted or internet-facing networks. No public proof of concept is known, EPSS estimates a 0.4% probability of exploitation within 30 days, and the flaw is not yet listed in CISA's KEV catalog.

What to do: Check TOTOLINK T6 units for firmware version 4.1.5cu.748_B20211015 and upgrade when TOTOLINK publishes a fixed release (no fixed version is identified in the available data). Until then, prevent untrusted or WAN-side network access to the router's MQTT/cloud-management interface so unauthenticated MQTT messages cannot reach cs_broker. No in-the-wild exploitation is currently known, but monitor TOTOLINK advisories for a patched firmware.

Affected
TOTOLINK T6 router (cs_broker component, remoteCloudUpdateCheck function)4.1.5cu.748_B20211015 (only version listed in the data; other versions not specified)
Estimated exposure
moderatelikely on the order of a few thousand internet-reachable devices at most (single consumer router model, single listed 2021 firmware build) — No install-base data was provided, but TOTOLINK budget routers historically appear in public internet scans in the tens of thousands across all models, so restricting to the T6 on this one firmware build plausibly leaves only a few…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to restart the cloud update check workflow via sending a crafted MQTT message to the cs_broker component.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.