Description
Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mesh slaves via sending a crafted MQTT message to the cs_broker component.
Published: 2026-09-01
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized device reboot via MQTT
Action: Patch or Mitigate
AI Analysis

Impact

The setDevReboot function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 contains an access control flaw that permits any attacker to trigger a router reboot without credential verification. When an attacker sends a crafted MQTT message to the cs_broker component, a master device will reboot itself, and on a mesh network it will propagate the reboot command to all associated slave nodes. The resulting loss of connectivity can disrupt network services and temporarily deny access to users, with significant availability impact, but does not directly compromise data confidentiality or integrity.

Affected Systems

Affected devices are TOTOLINK T6 routers running firmware version 4.1.5cu.748_B20211015. No other product or version data is currently reported.

Risk and Exploitability

The vulnerability is exploitable through an unauthenticated MQTT interface, an attack path that requires the attacker to have network access to the router. The CVSS score of 7.5 indicates a high severity. It remains not listed in CISA KEV, and the EPSS score is not published. Operators should evaluate the risk as significant enough to warrant prompt mitigation or patching if an update becomes available.

Generated by OpenCVE AI on September 2, 2026 at 04:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update for TOTOLINK T6 once it is released
  • Configure firewall or ACL rules to block unauthorized MQTT traffic to the cs_broker endpoint
  • Disable or restrict the cs_broker service if the device does not function as a master or require MQTT-based reboots

Generated by OpenCVE AI on September 2, 2026 at 04:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Device Reboot via MQTT in TOTOLINK T6

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Device Reboot via MQTT in TOTOLINK T6
First Time appeared Totolink
Totolink t6
Vendors & Products Totolink
Totolink t6
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mesh slaves via sending a crafted MQTT message to the cs_broker component.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T15:02:05.766Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51766

cve-icon Vulnrichment

Updated: 2026-09-01T15:01:20.877Z

cve-icon NVD

Status : Deferred

Published: 2026-09-01T14:17:37.143

Modified: 2026-09-01T21:00:36.830

Link: CVE-2026-51766

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:30:04Z

Weaknesses