Executive brief
TOTOLINK T6 is a wireless mesh router used to provide network connectivity and remote management capabilities. An unauthenticated attacker can trigger unintended reporting of static device information to a remote master server by sending a specially crafted MQTT message, potentially exposing device configuration details and disrupting normal device operation.
Technical details
This is an incorrect access control vulnerability in the staticInfoSend function of the cs_broker component in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The vulnerability allows an unauthenticated attacker to craft and send a malicious MQTT message to the cs_broker component without authentication, triggering the staticInfoSend function to report static information to a configured master device. The attack requires network access to the device and MQTT connectivity but no authentication credentials. An attacker can leverage this to exfiltrate device configuration or disrupt device management operations. No public patch information is currently available.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-09-01: disclosed