Executive brief
The TOTOLINK T6 router's guest WiFi management function contains an access control flaw that allows unauthenticated remote attackers to disable guest virtual WiFi networks. An attacker can send a specially crafted MQTT message to the device's internal message broker to disable guest access points, disrupting legitimate guest network functionality and potentially locking authorized users out of guest connectivity.
Technical details
The vulnerability is an authentication bypass in the guest_wifi_sync function of the TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated attackers to send MQTT messages directly to the cs_broker component without any access control checks. By crafting malicious MQTT messages targeting the guest_wifi_sync function, attackers can disable guest virtual AP (access point) interfaces. The attack requires network access to the device's MQTT broker but no authentication credentials. The impact is denial of service to guest WiFi functionality.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-09-01: disclosed