External risk intelligence

TOTOLINK T6 Mesh Record Manipulation Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51765

The vulnerability involves an MQTT-based broker component within a consumer router. While network-reachable, MQTT brokers on home routers are typically intended for local mesh network communication and are not normally exposed directly to the public internet in standard deployments.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical security flaw in a specific networking device that allows unauthorized modification of its network configuration. The vulnerability, if exploited, could potentially disrupt network operations or lead to other malicious activities by allowing attackers to insert or replace important network information. The main concern is to confirm if this specific type of device is in use within our environment and if it is exposed in a way that could be targeted.

  • Attackers can alter network records remotely.
  • It affects specific network devices and their configurations.
  • Confirm relevance and potential exposure of affected devices.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can target the MQTT broker, a component responsible for managing mesh network information. By sending a specially crafted MQTT message, the attacker can insert or alter mesh neighbor records, potentially leading to significant disruption.

  • No authentication required.
  • Craft MQTT message to broker.
  • Manipulate mesh records.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to interfere with a router's mesh networking functionality by sending specially crafted messages. This interference could potentially disrupt network operations or allow for unauthorized modifications to the router's network configuration.

  • Router mesh neighbor records could be altered.
  • Crafted MQTT messages could be sent to the broker.
  • Network disruption or unauthorized configuration changes.

Operational Fix

Recommended remediation, mitigation, and detection steps

The TOTOLINK T6 router's mesh networking component is susceptible to unauthenticated manipulation of neighbor records via crafted MQTT messages. The primary teams likely involved in addressing this are infrastructure or network teams responsible for device management and security teams overseeing network perimeter and device hardening. The immediate practical step is to identify all deployed T6 routers, confirm their network exposure, and determine which are business-critical or customer-facing before planning remediation.

  • Infrastructure or network teams should own the issue.
  • Verify external reachability and business criticality.
  • Plan mesh network record validation and router updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TOTOLINK T6 router?

The TOTOLINK T6 is a consumer networking device designed to create or extend home mesh Wi-Fi networks. It uses internal messaging components to allow multiple units to communicate and manage how they share traffic. This specific model, version 4.1.5cu.748_B20211015, relies on an MQTT broker component to handle these mesh coordination tasks automatically.

What does CVE-2026-51765 mean by incorrect access control?

This vulnerability relates to CWE-284, which occurs when a system does not properly restrict who can interact with a sensitive function. In this case, the router's mesh management system lacks authentication, meaning it will accept and process instructions from anyone who can send messages to the device, rather than verifying they are a trusted part of the mesh network.

How is this mesh record manipulation triggered?

An attacker triggers this by sending a specially crafted MQTT message directly to the device's cs_broker component. The vulnerability is specifically about the mesh neighbor records; sending legitimate traffic intended for other router functions or normal internet browsing does not trigger this flaw. The device only becomes susceptible when it receives these specific, malformed control packets.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal indicates that while the T6 contains this flaw, active risk is unlikely for most setups. The MQTT broker is typically designed for local communication within your home or office mesh network and is not intended to be reachable from the public internet. If your router is configured for standard home use, it likely lacks the necessary external connectivity for an attacker to reach the broker.

What should I do if I use TOTOLINK T6 routers?

Begin by creating an inventory of any T6 devices in your environment to understand where they are deployed. Confirm whether any of these units have been mistakenly configured with public-facing settings that allow external access. Once identified, prioritize these routers for security hardening and watch for official firmware updates from the vendor that address the authentication flaw in the mesh messaging component.

References