Executive brief
TOTOLINK T6 is a mesh WiFi router used for home and office networking. An unauthenticated attacker can send a specially crafted MQTT message to bypass access controls in the mesh heartbeat function, potentially allowing them to manipulate mesh network topology and compromise network reliability or gain unauthorized control over the router's mesh operation.
Technical details
The vulnerability is an incorrect access control flaw in the keepAlive function of the cs_broker component in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. An unauthenticated attacker can craft a malicious MQTT message to bypass authentication checks and emit indirect mesh heartbeat information toward the master device in the mesh network. The attack requires network access to reach the cs_broker component but no prior authentication. Successful exploitation allows an attacker to interfere with mesh network communication and potentially disrupt normal operation or escalate to further attacks on the mesh topology.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-09-01: disclosed