External risk intelligence

TOTOLINK T6 Remote Device Removal and Reboot Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51751

The vulnerability affects a consumer-grade router component that processes MQTT messages. While mesh management services are often intended for internal network use, IoT and consumer networking devices are frequently misconfigured or exposed to the internet, making remote reachability possible depending on the specific deployment and user configuration.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in a TOTOLINK device's function that manages connected devices within a local network. This issue allows unauthenticated remote attackers to interfere with network management and reboot the system by sending a specially crafted message. The primary concern is confirming if this type of device and specific functionality are in use within our environment.

  • Unauthenticated remote attackers can disrupt network management.
  • This affects consumer routers and network management functions.
  • Confirm relevance and exposure within our environment.

Attack Path

How an attacker could exploit the issue

An attacker could target an exposed router to remotely remove slave devices and reboot the system. This is possible by sending a specially crafted MQTT message to the router's message broker, which then interacts with the vulnerable `delSlaveDevice` function.

  • No authentication required.
  • Triggered by a crafted MQTT message.
  • Remote device removal and system reboot.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to disrupt the operation of a TOTOLINK router by removing a connected device from its mesh network and causing the system to reboot. This could occur when the router is accessible over a network and processes specially crafted MQTT messages.

  • Slave device management data.
  • Unauthenticated network message.
  • Service disruption and reboot.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in a consumer router's mesh management component could allow unauthenticated attackers to disrupt network operations by removing slave devices and rebooting the system. Owners of this technology, likely consumer or small business IT support, should first identify all instances of the affected device, confirm its network exposure and business criticality, and then determine the accountable party for remediation.

  • Identify device instances and exposure.
  • Confirm business criticality and ownership.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TOTOLINK T6 router and what is it used for?

The TOTOLINK T6 is a consumer-grade router designed to provide network connectivity, often featuring mesh networking capabilities. In home or small office environments, it manages local traffic and coordinates connections between multiple devices within the mesh network, relying on internal components like the MQTT message broker to handle system commands.

What does CWE-284 mean for CVE-2026-51751?

CWE-284 identifies this as an Improper Access Control vulnerability. In the context of CVE-2026-51751, it means the router's software lacks the necessary security checks to verify who is sending a request. Because the system fails to validate the sender's identity, an unauthorized user can issue commands that should be restricted, such as removing mesh devices or triggering a reboot.

How is this CVE-2026-51751 vulnerability triggered?

The vulnerability is triggered when an attacker sends a specially crafted MQTT message to the router's cs_broker component. The system then processes this malicious message through the delSlaveDevice function without checking for authentication. Simply accessing the network is sufficient; legitimate administrative actions or valid mesh configurations are not required to initiate this process.

Is my network at risk according to Halo Surface Signal?

Halo Surface Signal indicates that while these mesh management services are generally intended for internal use, consumer devices are frequently misconfigured or exposed to the internet. If your TOTOLINK T6 is directly reachable from the internet rather than restricted to your local network, the risk of remote exploitation increases significantly.

How should I respond if I am running the TOTOLINK T6?

Your first priority is to locate all TOTOLINK T6 devices in your environment to understand their current role and business criticality. Verify whether these devices are accessible from the internet or limited to internal segments. Once identified, determine who is responsible for managing these units so you can monitor for official security updates or guidance from the manufacturer.

References