Executive brief
The TOTOLINK T6 router's cloud status tracking function lacks proper authentication checks, allowing an attacker on the local network to send a specially crafted MQTT message and overwrite critical cloud-result tracking files. This could disrupt the device's ability to communicate with cloud services or be used as part of a larger attack chain to compromise router operations.
Technical details
The vulnerability is an incorrect access control flaw in the recvSlaveCloudCheckStatus function of the cs_broker component in TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The function fails to properly authenticate requests before processing MQTT messages, allowing unauthenticated attackers to send crafted messages that overwrite cloud-result tracking files. The attack vector is network-based via MQTT and requires no authentication. An attacker can abuse this to modify cloud status records or potentially trigger unintended behavior in cloud synchronization routines. No patch information is currently available in the provided advisory.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-09-01: disclosed