Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-51611: TOTOLINK T6 router can be rebooted by anyone
CVE-2026-51611 · published 6 days ago
Summary
The TOTOLINK T6 device running version 4.1.5cu.748 allows anyone on the network to send a special MQTT message that forces the router to restart. This can cause temporary loss of connectivity and interrupt business operations. Apply the latest firmware update from the vendor or disable the MQTT feature until it is patched.
Original advisory text
Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a crafted MQTT message.
Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a crafted MQTT message.
References
- https://github.com/DarkBoulder/CVE-Vendor-Coordination/blob/main/TOTOLINK/202604...
- https://github.com/DarkBoulder/CVE-Vendor-Coordination/blob/main/TOTOLINK/202604...
- https://github.com/ShengWu00/CVE-Vendor-Coordination/blob/main/TOTOLINK/README.m...
- https://www.totolink.net/
- https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/190/ids/36.ht...
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published28 Aug 2026
Updated3 Sep 2026
First seen28 Aug 2026
Monitor software like this
Free during beta