Executive brief
The TOTOLINK T6 is a network device (wireless router/switch) used to manage connected client devices and network configuration. An unauthenticated attacker can send a specially crafted MQTT message to modify stored inventory records of connected devices, potentially enabling unauthorized network management and control of slave devices.
Technical details
This is an access control bypass vulnerability in the sendStaticInfoToMaster function within the cs_broker component of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The vulnerable function fails to authenticate incoming MQTT messages, allowing any network-attached attacker to send crafted messages and modify slave device inventory records. The attack requires network connectivity to the device's MQTT broker but no credentials or user interaction. Successful exploitation enables attackers to alter stored device information, potentially disrupting device management operations or enabling lateral movement within the managed network.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-09-01: disclosed