Executive brief
TOTOLINK T6 is a mesh networking router device used to extend and manage wireless coverage in homes and offices. An unauthenticated attacker can send a crafted MQTT message to manipulate mesh neighbor records, potentially disrupting network topology and enabling unauthorized network management operations. This allows attackers on the network to gain control over critical mesh connectivity without any password or authentication.
Technical details
The vulnerability is an incorrect access control flaw in the recvIndirectMeshInfo function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The function fails to properly validate authentication before processing MQTT messages targeting the cs_broker component, allowing unauthenticated attackers to insert or replace mesh neighbor records. The attack vector is network-based and requires only the ability to send an MQTT message to the broker; no prior authentication or user interaction is needed. Exploitation enables attackers to modify mesh network topology and potentially facilitate further network compromise or denial of service. Patch availability for this vulnerability has not been confirmed in the advisory.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-09-01: disclosed