Executive brief
TOTOLINK T6 is a home networking device used for WiFi connectivity and device pairing. A flaw in the recvClearPairCfg function allows unauthenticated attackers to send malicious MQTT messages that reset the device's pairing state and force a reboot, disrupting network operations and potentially locking users out of device management.
Technical details
The recvClearPairCfg function in the cs_broker component fails to validate user authentication before processing MQTT messages that control pairing state and device reboot operations. An unauthenticated attacker on the network can craft and send malicious MQTT packets to trigger pairing reset and device reboot without any credentials or prior interaction. This is a broken access control vulnerability (CWE-284) that requires only network reachability to the MQTT broker. No patch information is publicly available at this time.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-09-01: disclosed