Junglewise Threat Intelligence

CVE-2026-51766: TOTOLINK T6 incorrect access control in setDevReboot

CVE-2026-51766 · Severity: high · CVSS 7.5 · Published 2026-09-01

Vendors: TOTOLINK.

Executive brief

TOTOLINK T6 routers are mesh-capable WiFi systems used in homes and small businesses to extend network coverage. A missing authentication check in the device reboot function allows an attacker on the network to reboot the router and cascade reboot commands to other mesh devices without any credentials, causing service disruptions and potentially enabling further attacks during the restart window.

Technical details

The vulnerability is an authentication bypass (missing access control) in the setDevReboot function of the cs_broker component in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker with network access can send a crafted MQTT message to the cs_broker component to trigger device reboot. On master nodes in a mesh topology, the vulnerability also allows the attacker to fan out reboot commands to slave devices in the mesh. No authentication credentials are required and the attack is initiated via the network-accessible MQTT broker. This results in uncontrolled device restarts that can disrupt network availability and operations.

Affected products

  • TOTOLINK T6 4.1.5cu.748_B20211015

Timeline

  • 2026-09-01: disclosed

References