Executive brief
TOTOLINK T6 is a mesh networking router used to extend wireless coverage in homes and offices. The device's mesh management system lacks proper authentication checks, allowing an attacker to send a crafted message to remove connected devices and force a system reboot without needing any credentials, potentially disrupting network operations and causing data loss.
Technical details
The vulnerability is an authentication bypass in the delSlaveDevice function within the cs_broker component of TOTOLINK T6 firmware 4.1.5cu.748_B20211015. An unauthenticated attacker can craft a malicious MQTT message and send it to the cs_broker component to remove a slave device from the mesh network's local management data and trigger a system reboot. The attack is network-accessible and requires no user interaction or credentials. The root cause is missing access control validation in the function, allowing any caller to invoke privileged operations.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-09-01: disclosed