External risk intelligence

TOTOLINK T6 MQTT Pairing Reset and Reboot Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51767

The vulnerability involves an MQTT broker component within a consumer-grade router. While network-reachable, MQTT services on such devices are typically intended for internal management or local communication and are generally not exposed directly to the public internet in standard deployments.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security vulnerability has been identified in certain TOTOLINK networking devices, specifically related to how they handle pairing state and device reboots. This issue could allow unauthenticated attackers to interfere with the device's configuration by sending specially crafted messages. The main concern is to confirm if these devices and the affected component are in use within our environment.

  • Unauthenticated attackers can reset device settings.
  • Relevant for network device security posture.
  • Confirm device exposure and impact.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can remotely target the device's MQTT broker by sending a specially crafted MQTT message. This message can exploit a flaw in the `recvClearPairCfg` function, allowing the attacker to reset the device's pairing state. This action can lead to a device reboot, disrupting its normal operation.

  • No authentication required for access.
  • Triggered by crafted MQTT message.
  • Unauthenticated control and reboot.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker could exploit this vulnerability by sending a specially crafted MQTT message to a router's MQTT broker. This could allow them to reset the device's pairing state and reboot it, disrupting its normal operation.

  • Router pairing state and reboot.
  • Sending crafted MQTT messages.
  • Service disruption and unauthorized resets.

Operational Fix

Recommended remediation, mitigation, and detection steps

The TOTOLINK T6 router's MQTT component is affected by this vulnerability, suggesting that network or infrastructure teams managing these devices, alongside vendor management teams, should take the lead. The first critical step is to inventory all deployed TOTOLINK T6 devices, determine their network exposure, identify business criticality, and confirm the accountable owner for remediation planning.

  • Own the issue and asset inventory.
  • Verify device network exposure.
  • Plan remediation and vendor engagement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TOTOLINK T6?

The TOTOLINK T6 is a consumer-grade wireless router used to manage home or small office network connectivity. It includes internal software components that facilitate device communication and management features, such as the MQTT broker, which handles messaging between the router and connected services.

What does CVE-2026-51767 mean for device security?

This vulnerability is classified as an improper access control issue (CWE-284). It means the device fails to verify who is sending commands, allowing an attacker to interact with restricted functions without proving their identity. In this specific case, it grants unauthorized access to the pairing configuration.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a specially crafted MQTT message to the device's broker component. It does not require physical access, but it does not occur through standard web traffic; the attacker must be able to communicate directly with the MQTT service, which is not triggered by typical internet browsing.

Is my TOTOLINK T6 at risk?

Halo Surface Signal indicates the risk is unlikely for most users because the affected MQTT service is designed for internal management, not public internet access. Devices are typically only at risk if they have been explicitly configured to expose internal management ports to the public internet.

Do I need to take action if I use this router?

Yes, begin by inventorying all TOTOLINK T6 devices in your environment to understand where they are deployed. Confirm whether any management interfaces are accessible from outside your local network, and contact the vendor to track available updates for the affected software version.

References