External risk intelligence

TOTOLINK T6 MQTT Unauthenticated Client Disconnection

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51763

The vulnerability resides in a home router's wireless management component. Since routers are edge devices and the flaw is reachable via unauthenticated MQTT messages, it is highly accessible from the local network and potentially the internet depending on router configuration.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security vulnerability has been identified in a widely used home router component, allowing unauthenticated attackers to disrupt wireless connections by sending specially crafted messages. This could impact the availability of network services for users connected to the affected devices.

  • Attackers can disconnect users from Wi-Fi.
  • Routers are network entry points, demanding attention.
  • Confirm relevance and potential exposure to the business.

Attack Path

How an attacker could exploit the issue

An attacker can disrupt the network by sending a specially crafted message to the router's MQTT broker. This message exploits a flaw in how the router manages client connections, allowing the attacker to force wireless devices off the network without needing any credentials. The vulnerability can lead to a denial-of-service condition where legitimate users lose internet access.

  • No authentication required to attack.
  • Crafted MQTT message triggers disconnection.
  • Disrupts wireless client connectivity.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in TOTOLINK routers could allow unauthenticated attackers to disrupt wireless network service by sending a specially crafted MQTT message to the `cs_broker` component. This could lead to unexpected disconnections for legitimate wireless clients connected to the router.

  • Wireless client connections at risk.
  • Attackers can send crafted MQTT messages.
  • Network service disruption may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in TOTOLINK routers impacts device owners and network administrators. The immediate first step is to identify all deployed TOTOLINK T6 routers, assess their network exposure, and determine business criticality to prioritize remediation efforts and engage the vendor for a solution.

  • Device owners must triage this issue.
  • Verify device exposure and criticality first.
  • Coordinate with the vendor for a fix.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TOTOLINK T6?

The TOTOLINK T6 is a wireless router designed for home networking. It acts as a central hub, managing connectivity for multiple devices and routing traffic between the local network and the internet. The affected software component, specifically the MQTT broker, is used by the device to handle internal messaging and status updates for wireless clients.

What does CVE-2026-51763 mean?

This CVE indicates an Improper Access Control vulnerability, classified under CWE-284. In plain terms, the router fails to verify who is sending commands to its internal messaging system. Because of this, the device blindly accepts instructions from unauthorized sources, which in this case allows someone to manipulate the state of connected wireless devices.

How can an attacker trigger this issue?

An attacker triggers this vulnerability by sending a specifically formatted MQTT message to the router's cs_broker component. No interaction from a legitimate user or valid login credentials are required. Simply sending the malicious message is sufficient; standard network traffic or normal administrative actions do not cause this disconnection.

Is my device at risk of this attack?

Halo Surface Signal notes that this vulnerability is highly accessible because routers function as edge devices. If your router is configured to allow traffic from the local network, or if it is exposed to the internet, you are at higher risk. This flaw specifically targets the wireless management layer, meaning any device connected to the network could potentially be forced offline.

What steps should I take to respond?

Start by identifying all TOTOLINK T6 routers within your environment. Once identified, evaluate whether these devices are accessible from the internet or restricted to internal traffic. Since this impacts availability, prioritize this for your edge devices and contact the vendor directly for official guidance, firmware updates, or documented workarounds to secure the MQTT broker.

References