Executive brief
TOTOLINK T6 is a WiFi mesh router used in home and small business networks. This vulnerability allows unauthenticated attackers to change Quality of Service (QoS) settings on the device by sending a specially crafted message to an internal component. An attacker could degrade network performance, prioritize malicious traffic, or disrupt legitimate users' connectivity.
Technical details
The vulnerability is an access control flaw in the sendToMasterQosConfig function within the cs_broker component of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The function fails to validate that the sender is authenticated before processing QoS configuration changes intended for the master device. An unauthenticated attacker can send a crafted MQTT message to the cs_broker to modify QoS settings without authorization. The attack vector is network-based and requires no user interaction. An attacker can manipulate network traffic prioritization and settings on the affected device.
Affected products
- TOTOLINK T6 4.1.5cu.748_B20211015
Timeline
- 2026-09-01: disclosed