Executive brief
The TOTOLINK T6 mesh router firmware (version 4.1.5cu.748_B20211015) contains a flaw that allows unauthenticated attackers to initiate firmware downloads or updates on slave devices by sending specially crafted messages through the internal MQTT broker. This could allow remote attackers to compromise the device or disrupt network operations by forcing unauthorized firmware installations.
Technical details
The vulnerability is an access control bypass in the meshSlaveUpdate function of TOTOLINK T6 firmware. The function fails to properly validate the origin or credentials of MQTT messages sent to the cs_broker component, allowing unauthenticated attackers to send crafted payloads that trigger firmware download or flashing workflows on slave mesh devices. The flaw requires network access to the router's MQTT broker but does not require authentication. A successful exploit results in arbitrary firmware execution on the affected device, leading to complete device compromise.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-09-01: disclosed