External risk intelligence

TOTOLINK T6 Unauthenticated File Overwrite via MQTT

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51764

The vulnerability affects a TOTOLINK router, which is typically deployed as an internet-facing edge device. The exploit involves sending crafted MQTT messages to the device's broker component, which is a common network service for such appliances, making the attack surface reachable from the network edge in standard deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in certain TOTOLINK networking devices, specifically affecting a function responsible for checking cloud status. This flaw allows unauthenticated attackers to potentially overwrite important tracking files by sending a specially crafted message, posing a significant security risk due to its network-accessible nature and high severity.

  • Unauthenticated attackers can overwrite device tracking files.
  • This affects internet-facing network devices.
  • Confirm relevance and assess exposure to this critical issue.

Attack Path

How an attacker could exploit the issue

An attacker can reach this vulnerability by sending specially crafted MQTT messages to the router's broker component from the internet. This bypasses access controls, allowing them to overwrite critical files related to cloud tracking. The vulnerability can lead to a complete compromise of the device's tracking capabilities.

  • No authentication required.
  • Overwrite cloud tracking files.
  • Full device tracking compromise.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could overwrite cloud-result tracking files on TOTOLINK T6 routers by sending a crafted MQTT message. This could affect the router's ability to accurately track cloud status when supported by the advisory.

  • Router cloud-result tracking files at risk.
  • Overwriting via crafted MQTT messages.
  • Disruption of cloud status tracking.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in TOTOLINK routers likely impacts network infrastructure or IoT platform teams responsible for managing edge devices. The initial practical step is to identify all deployed TOTOLINK routers, confirm their internet reachability and business criticality, and then assign an owner to plan remediation, which may involve coordination with the vendor.

  • Network or IoT platform teams own remediation.
  • Verify internet-facing router exposure and criticality.
  • Plan vendor-coordinated firmware updates or replacements.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TOTOLINK T6 and what is it used for?

The TOTOLINK T6 is a networking device typically used as a router to manage home or office internet traffic. It serves as a gateway to connect local devices to the internet and often includes features for cloud-based status monitoring to help users manage their connection settings and remote configurations.

What does CWE-284 mean for CVE-2026-51764?

CWE-284 refers to Improper Access Control. In the context of this vulnerability, it means the router fails to properly check if a user is authorized before performing sensitive tasks. Because of this flaw, the device will accept and process instructions—specifically, commands that overwrite important system files—without requiring any login or proof of identity from the sender.

How does an attacker trigger this vulnerability?

An attacker triggers this flaw by sending a specially crafted MQTT message directly to the router's cs_broker component. The vulnerability is specifically limited to the processing of these messages within the 'recvSlaveCloudCheckStatus' function; it does not occur through standard web interface interactions or manual configuration changes made by an authorized administrator.

Is my device at risk based on Halo Surface Signal?

Yes, if you use a TOTOLINK T6. Halo Surface Signal identifies this as a 'Likely' risk because these routers function as internet-facing edge devices. Since the MQTT broker service is often reachable from the network edge in standard configurations, an attacker can send malicious messages from the internet to your device without needing to be on your local network.

How should I respond to this vulnerability?

Start by auditing your network to identify any deployed TOTOLINK T6 units. Once identified, evaluate whether these devices are exposed to the internet. Determine their business criticality and coordinate with the vendor or your technical lead to check for available firmware updates or security patches that address the improper access control in the broker component.

References