ZeroHour

CVE-2026-51770

moderate

Incorrect access control in TOTOLINK T6 lets attackers push QoS settings via MQTT

CVSS 3.1
9.8 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-51770 is an incorrect access-control flaw (CWE-284) in the sendToMasterQosConfig function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker who can reach the device's cs_broker MQTT component can send a crafted MQTT message that causes the T6 node to forward attacker-controlled QoS settings to the master unit in a mesh deployment. This allows unauthorized modification of QoS/traffic-shaping configuration on the master device without any credentials, and the 9.8 CVSS score indicates potentially high impact on confidentiality, integrity, and availability. Owners and operators of TOTOLINK T6 mesh nodes running the named firmware are affected, especially where the MQTT service is reachable from untrusted networks. No exploitation is currently known: there is no public PoC, the flaw is not in CISA KEV, and EPSS assigns a 0.4% probability of exploitation within 30 days (37th percentile).

What to do: Verify the running firmware on T6 nodes and upgrade to a fixed release from TOTOLINK when one is published (no fixed version is specified in the available data). Until then, do not expose the cs_broker MQTT service or remote management to the WAN, and restrict MQTT access with firewall rules. Monitor TOTOLINK advisories for confirmation of the full affected version range.

Affected
TOTOLINK T64.1.5cu.748_B20211015 (only version cited in the advisory; whether other builds are affected is not stated)
Estimated exposure
moderateon the order of tens of thousands of T6 units deployed, with likely only a few thousand internet-exposed (estimate) — No published install counts exist for the T6, but TOTOLINK consumer routers routinely appear in public internet scans in the tens of thousands across all models, and a single mesh product line is plausibly a low-tens-of-thousands…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS settings to the master via sending a crafted MQTT message to the cs_broker component..

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.