External risk intelligence

TOTOLINK T6 Mesh Configuration Synchronization Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51744

The vulnerability resides in a consumer networking device's mesh synchronization component, which processes external MQTT messages. As a network gateway/router feature designed to receive and process traffic, this interface is exposed to the network edge, making it public-facing by design.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in TOTOLINK's mesh networking technology, specifically affecting how devices synchronize configuration. This issue allows unauthenticated attackers to remotely manipulate these devices by sending specially crafted messages, potentially leading to widespread disruption. The main concern is confirming relevance and exposure within our environment.

  • Unauthenticated remote control of mesh network settings.
  • Matters because it impacts core network infrastructure.
  • Confirm relevance and exposure of affected devices.

Attack Path

How an attacker could exploit the issue

An attacker can remotely send a specially crafted MQTT message to the device's `cs_broker` component. This message targets the `recv_mesh_info_sync` function, which lacks proper access controls, allowing unauthenticated users to initiate a mesh configuration synchronization with an attacker-controlled host.

  • No authentication is needed.
  • Crafted MQTT message triggers sync.
  • Complete device control possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to force mesh configuration synchronization from a controlled host by sending a crafted MQTT message. This could affect the mesh network's configuration and behavior.

  • Network configuration data at risk.
  • Unauthenticated network access.
  • Mesh network disruption or control.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in TOTOLINK mesh synchronization affects network infrastructure devices. The first action should be to identify all deployed instances, determine their network exposure and criticality, and locate the accountable owner. Subsequent steps will depend on this assessment, potentially involving vendor coordination or temporary risk reduction measures.

  • Own by Network or Infrastructure teams.
  • Verify device reachability and criticality.
  • Plan coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TOTOLINK T6 and what is its role?

The TOTOLINK T6 is a consumer-grade wireless router designed to provide home or small office internet connectivity. It includes mesh networking capabilities, which allow multiple units to communicate and form a unified, wider-coverage wireless network throughout a space.

What does CWE-284 mean for CVE-2026-51744?

CWE-284 refers to Improper Access Control. In the context of this vulnerability, it means the software fails to verify who is sending a command before executing it. Specifically, the device accepts mesh synchronization instructions from any source, even if the sender has not proven they are an authorized administrator.

How can an attacker trigger this vulnerability?

An attacker can trigger this by sending a specially crafted MQTT message to the device's cs_broker component. The vulnerability is not triggered by normal wireless traffic or general web browsing; it requires the attacker to successfully communicate with the specific messaging protocol component that the router uses for internal synchronization tasks.

Is my device affected by this CVE?

Halo Surface Signal indicates that because this vulnerability exists within a network gateway feature designed to process external traffic, these devices are public-facing by design. If you have a TOTOLINK T6 configured as part of a mesh network, the interface responsible for processing these messages is likely reachable, increasing the risk of unauthorized interaction from the network edge.

Do I need to take action if I use this router?

Yes. Start by identifying all TOTOLINK T6 devices in your environment and confirming their specific firmware versions. Once mapped, coordinate with your network or infrastructure teams to assess the criticality of these devices and determine if they can be isolated from the public internet until official guidance or updates are provided.

References