Junglewise Threat Intelligence

CVE-2026-51611: TOTOLINK T6 arbitrary reboot via unauthenticated MQTT message

CVE-2026-51611 · Severity: critical · CVSS 9.8 · Published 2026-08-28

Vendors: TOTOLINK.

Executive brief

The TOTOLINK T6 router contains a flaw in its MQTT message handling that allows unauthenticated attackers to remotely force a device reboot without requiring authentication. An attacker with network access to the router can send a specially crafted MQTT message to trigger an immediate reboot, causing network service disruption and potential data loss.

Technical details

The vulnerability exists in the startSlaveReboot function within TOTOLINK T6 firmware version 4.1.5cu.748_B20211015, which implements improper access control for MQTT message processing. The function fails to validate or enforce authentication before accepting reboot commands received via MQTT, allowing any unauthenticated network-adjacent attacker to trigger a device restart. The attack vector requires network access to the MQTT service (typically port 1883), and no user interaction or prior authentication is needed. An attacker can exploit this to cause repeated service interruptions or create a denial-of-service condition. Patches or firmware updates addressing this issue should be available from TOTOLINK.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-08-28: disclosed

References