Executive brief
TOTOLINK T6 is a router that manages network configuration. An unauthenticated attacker can send a crafted MQTT message to modify the device's LAN IP address settings without providing login credentials, potentially disrupting network connectivity or facilitating further attacks on the device or connected network.
Technical details
The updateLanIp function in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015 lacks proper access control checks, allowing unauthenticated MQTT messages to trigger changes to LAN configuration. The vulnerability exists in the cs_broker component, which processes incoming MQTT messages. An attacker with network access to the MQTT interface can send a crafted message to modify LAN IP settings without authentication. This represents a missing authentication vulnerability in the MQTT message handling code path.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-09-01: disclosed