External risk intelligence

TOTOLINK T6 Unauthenticated Reboot via MQTT Message

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51611

The vulnerability exists in a home networking router (TOTOLINK T6). These devices are commonly deployed as internet-facing gateways, often exposing management interfaces or services to the public network or WAN, making them reachable in common real-world deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security flaw has been identified in TOTOLINK networking devices that allows unauthenticated attackers to remotely force a device reboot by sending a specially crafted message. This could disrupt network services and operations.

  • Attackers can reboot devices remotely.
  • Home routers often face the internet.
  • Confirm if this device type is in use.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could target the TOTOLINK T6 router by sending a specially crafted MQTT message. This message would exploit an access control weakness in the `startSlaveReboot` function, allowing the attacker to force the device to reboot.

  • No authentication required.
  • Triggered by a crafted MQTT message.
  • Can cause device reboot.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could trigger a device reboot by sending a specially crafted MQTT message. This could disrupt network connectivity for users connected to the affected device when supported by the advisory.

  • Device availability.
  • Network disruption via crafted message.
  • Intermittent connectivity loss.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world action likely falls to network or infrastructure teams responsible for managing internet-facing devices, with potential involvement from vendor management if the device is customer-provided or managed by a third party. The first practical step is to identify all instances of the affected technology, confirm their reachability and criticality, and then assign an owner for remediation planning.

  • Own by network or infrastructure teams.
  • Verify device reachability and criticality.
  • Plan remediation or risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TOTOLINK T6?

The TOTOLINK T6 is a networking device typically used as a home router. It functions as a gateway to manage and route internet traffic for connected devices within a local network environment.

What does CVE-2026-51611 mean for the TOTOLINK T6?

This CVE refers to an incorrect access control weakness, categorized as CWE-284. It means the router fails to properly restrict who can execute certain administrative functions. Specifically, the system allows unauthorized commands to bypass security checks, which is the root cause of this vulnerability.

How is the reboot vulnerability triggered?

An attacker can trigger the reboot by sending a specially crafted MQTT message to the device. Because the function responsible for this action lacks authentication, no valid credentials or prior login are required. Simply interacting with the device through this message protocol is sufficient to initiate the reboot process.

Is my TOTOLINK T6 at risk from this vulnerability?

According to Halo Surface Signal, this risk is likely if your device acts as an internet-facing gateway. Because these routers are commonly deployed with services reachable from the public network or WAN, they are often exposed to external, unauthenticated traffic, increasing the likelihood that an attacker could reach the vulnerable component.

What should I do if I use a TOTOLINK T6?

Start by identifying all instances of this specific device model within your network infrastructure. Assess how each unit is connected and confirm if its management services are reachable from the internet. Once located, verify the device's role in your environment and coordinate with your network or infrastructure team to plan for updates or necessary risk mitigation steps.

References