CVE-2026-51769
moderateUnauthenticated access control flaw in TOTOLINK T6 MQTT cloud update check
CVE-2026-51769 is an incorrect access control issue (CWE-284) in the remoteCloudUpdateCheck function of the cs_broker component in TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can trigger it by sending a crafted MQTT message directly to the cs_broker component, requiring no credentials or user interaction. The documented impact is the ability to restart the device's cloud update check workflow, which can force unexpected cloud-update activity; the assigned CVSS 3.1 base score is 9.8 (critical), indicating high confidentiality, integrity, and availability impact. Any TOTOLINK T6 router running firmware 4.1.5cu.748_B20211015 is affected, particularly units whose MQTT/cs_broker interface is reachable from untrusted or internet-facing networks. No public proof of concept is known, EPSS estimates a 0.4% probability of exploitation within 30 days, and the flaw is not yet listed in CISA's KEV catalog.
What to do: Check TOTOLINK T6 units for firmware version 4.1.5cu.748_B20211015 and upgrade when TOTOLINK publishes a fixed release (no fixed version is identified in the available data). Until then, prevent untrusted or WAN-side network access to the router's MQTT/cloud-management interface so unauthenticated MQTT messages cannot reach cs_broker. No in-the-wild exploitation is currently known, but monitor TOTOLINK advisories for a patched firmware.
| TOTOLINK T6 router (cs_broker component, remoteCloudUpdateCheck function) | 4.1.5cu.748_B20211015 (only version listed in the data; other versions not specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to restart the cloud update check workflow via sending a crafted MQTT message to the cs_broker component.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.