Executive brief
The TOTOLINK T6 router's mesh management function lacks proper authentication checks, allowing unauthenticated attackers to disrupt mesh networking by kicking devices or clearing mesh state information. An attacker can send crafted MQTT messages to trigger regeneration of mesh metadata, potentially disrupting network stability and connectivity for home or business users relying on mesh networking features.
Technical details
The meshInfoKick function in TOTOLINK T6 firmware 4.1.5cu.748_B20211015 fails to properly validate user authentication before processing requests. The vulnerability allows unauthenticated attackers to craft MQTT messages sent to the cs_broker component to kick mesh nodes or clear stale mesh information, forcing mesh topology recalculation. This is an access control bypass (CWE-284) with a network attack vector; no authentication or special credentials are required. An attacker with network access to the device can send malicious MQTT messages to disrupt mesh network operations or trigger denial-of-service conditions.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-09-01: disclosed