Executive brief
TOTOLINK T6 is a mesh WiFi router device used in homes and small businesses. An authentication bypass vulnerability allows unauthenticated attackers to modify QoS (Quality of Service) policies on the device by sending specially crafted MQTT messages, potentially degrading network performance or disrupting service for legitimate users.
Technical details
The vulnerability exists in the setElinkQosConfig function of the cs_broker component, which handles MQTT message processing. The function fails to properly validate that the requester is authenticated before allowing changes to QoS policy settings on the master device. An unauthenticated attacker with network access to the MQTT broker can send a crafted message to modify privileged QoS configurations. No authentication or special user interaction is required; the attack is triggered by network-reachable MQTT messaging.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-09-01: disclosed