External risk intelligence

TOTOLINK T6 MQTT Unauthenticated Slave IP Overwrite

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51754

This vulnerability affects a home router device (TOTOLINK T6). Routers are commonly deployed as internet-facing edge gateways. While the specific MQTT component may not always be exposed to the WAN, the nature of this product role makes it a typical candidate for internet-reachable network management services.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a network device that could allow unauthorized access and modification of its configuration. While the specific impact is still under investigation, the nature of the affected device and the severity of the vulnerability warrant attention to confirm its relevance to our environment.

  • Unauthenticated attackers can alter device settings.
  • Routers are common internet-facing gateways.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could send a malicious MQTT message to the router's broker. This message could trick the device into accepting a falsified list of trusted devices, potentially allowing the attacker to gain unauthorized control over the router and its network.

  • No authentication required.
  • Crafted MQTT message to broker.
  • Unauthorized control of network.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could overwrite the slave IP inventory by sending a crafted MQTT message to the cs_broker component. This could impact the integrity of the device's network configuration.

  • Device's slave IP inventory.
  • Via crafted MQTT message.
  • Integrity of network configuration.

Operational Fix

Recommended remediation, mitigation, and detection steps

Asset owners and infrastructure teams are likely responsible for addressing this vulnerability, as it affects a home router. The first practical step is to identify all instances of the affected device, confirm their exposure to the internet and business criticality, and then assign ownership for remediation planning.

  • Identify affected device instances.
  • Verify internet exposure and criticality.
  • Plan remediation with accountable owner.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TOTOLINK T6?

The TOTOLINK T6 is a home networking router designed to manage internet connectivity for connected devices. It acts as a central gateway, routing traffic between your local devices and the internet. The affected firmware version, 4.1.5cu.748_B20211015, includes a specific internal component called cs_broker that handles message communications within the device architecture.

What does CVE-2026-51754 mean in plain English?

This vulnerability is classified as Improper Access Control (CWE-284). It means the router fails to verify whether a user is authorized to perform specific actions. In this case, the system allows an unauthenticated person to overwrite the device's internal list of trusted 'slave' IP addresses. Because there is no security check, the device blindly accepts commands to change its own configuration.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a specially crafted MQTT message directly to the router's cs_broker component. Because the system does not require authentication, simply reaching this component with the right message is enough to overwrite the IP list. Normal web traffic or standard router usage that does not involve sending MQTT messages to this specific internal service will not trigger the bug.

Why should I care about this router vulnerability?

Halo Surface Signal flags this as a priority because routers like the TOTOLINK T6 are typically deployed as edge gateways, meaning they are frequently positioned between your local network and the internet. While not every component is reachable from the WAN, the critical nature of a router makes it a primary candidate for external scanning and potential targeting by unauthorized parties.

How do I respond if I use TOTOLINK T6 devices?

Start by performing an inventory to locate all active TOTOLINK T6 routers in your environment. Once identified, verify if these devices are directly accessible from the internet or if they are isolated behind other security controls. Determine who owns the devices and begin planning for configuration changes or updates to mitigate the risk of unauthorized network configuration changes.

References